Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
5033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.43% | — | Wpdataaccess WP Data AccessAI | 9/8/2026 | 26/8/2026 | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to,… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Pendiente de análisis | Media (6.3) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it against the backend. This requires a… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase (the user's full in-app search history).… | |
| Pendiente de análisis | Media (6.4) | 0.29% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally cancels notification ID 9201 (the Bits AI… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Datadog Android ApplicationAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported with no permission guard. Each accepts a… | |
| Pendiente de análisis | Media (6.5) | 0.34% | — | Datadog AndroidAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an arbitrary on-call page ID, and an arbitrary… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure SQL Database | 7/8/2026 | 8/8/2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.8) | 0.43% | — | DatapressAI | 6/8/2026 | 26/8/2026 | The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes the viewing user's data to it, allowing users with a role as low as Contributor to disclose sensitive information, such as the session cookies of higher privileged users… | |
| Aplazada | Baja (1.9) | 0.35% | — | DatagearAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlRenderer of the file HtmlTplDashboardWidgetHtmlRenderer.java of the component Chart Name Handler. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdataaccess WP Data AccessAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | WpdatatablesAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 7.5.1 versions. | |
| Aplazada | Alta (7.1) | 0.13% | — | Data443 Tracking Code ManagerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | |
| Analizada | Alta (8.3) | 0.14% | 💥 PoC | Thermofisher ABI Prism 310 Data Collection SoftwareThermofisher ABI Prism 3100/3100-avant Data Collection SoftwareThermofisher Applied Biosystems 3130 Series Data Collection SoftwareThermofisher Applied Biosystems 3500/3500xl Series Data Collection Software+4 | 5/8/2026 | 26/8/2026 | The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tamper with these files, altering DNA data and resulting in inaccurate DNA test outcomes. | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to sensitive internal claim locations. An attacker with a standard user… | |
| Modificada | Alta (8.1) | 0.46% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 5/8/2026 | 31/8/2026 | A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or matrix parameters to a URL, an attacker can trick the system into… | |
| Aplazada | Media (5.5) | 0.41% | — | Shandong Hoteam PDM Product Data Management SystemAI | 5/8/2026 | 12/8/2026 | A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is… | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Aplazada | Media (6.5) | 0.34% | — | Gdpr Framework BY Data443AI | 4/8/2026 | 26/8/2026 | The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording cookie-consent choices and privacy requests, allowing unauthenticated attackers to forge consent records for arbitrary email addresses and to flood the site's… | |
| Analizada | Alta (7.5) | 0.15% | — | Rrwo Data\ | 1/8/2026 | 7/8/2026 | Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. The Data::Entropy::RawSource::RandomOrg and Data::Entropy::RawSource::RandomnumbersInfo remote sources are accessed over plain HTTP. The Data::Entropy::RawSource::RandomOrg integrity check trivially matches any non-empty byte… | |
| Aplazada | Media (5.3) | 0.42% | — | Database Collation FIXAI | 1/8/2026 | 12/8/2026 | The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Xnau Participants DatabaseAI | 1/8/2026 | 26/8/2026 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Analizada | Alta (8) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips… | |
| Analizada | Alta (8) | 0.13% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to… | |
| Analizada | Media (6.6) | 0.24% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted… |