Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
5033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.71% | — | Koxudaxi Datamodel-code-generator | 28/7/2026 | 6/8/2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in… | |
| Aplazada | Alta (7.8) | 0.21% | — | Datamodel Code GeneratorAI | 28/7/2026 | 30/7/2026 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator/model/template/UnionTypeStatement.jinja2 and src/datamodel_code_generator/model/template/UnionTypeStatement.py312.jinja2 are rendered into Python comments… | |
| Aplazada | Alta (7.1) | 0.25% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/7/2026 | 28/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6) | 0.19% | — | Google MCP Toolbox FOR Databases | 27/7/2026 | 28/9/2026 | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport… | |
| Pendiente de análisis | Alta (7.7) | 0.57% | — | Kubevirt Containerized Data ImporterAI | 27/7/2026 | 21/9/2026 | In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:view ClusterRole, intended to provide read-only access to CDI resources, includes a rule granting create on the datavolumes/source subresource. CDI's DataVolume clone authorization accepts this permission as sufficient to authorize cloning the… | |
| Aplazada | Alta (7.5) | 0.74% | 💥 PoC | Datamodel Code GeneratorAI | 26/7/2026 | 12/8/2026 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim… | |
| Analizada | Media (6.9) | 0.79% | — | Huggingface Datasets | 24/7/2026 | 17/8/2026 | Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadata field is not properly validated before being joined to the dataset directory. Attackers can supply crafted file_name values with directory traversal sequences to read… | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Purview Data Governance | 24/7/2026 | 29/7/2026 | Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.3) | 0.42% | — | Xnau Participants DatabaseAI | 24/7/2026 | 24/7/2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing… | |
| Aplazada | Media (4.4) | 0.17% | — | Huggingface DatasetsAI | 23/7/2026 | 23/7/2026 | Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary filesystem locations in shared-cache… | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Aplazada | Crítica (10) | 0.60% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.63% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (4.4) | 0.15% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Database Server | 21/7/2026 | 6/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31 and 23.4.0-23.26.2. Easily exploitable vulnerability allows low privileged attacker having Execute DBMS_CLOUD privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management.… | |
| Analizada | Media (4.4) | 0.14% | — | Oracle Agile Engineering Data Management | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management… |