Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5034 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.29% | — | Data Roaringbitmap SharedAI | 21/7/2026 | 23/7/2026 | Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the header scalars and region layout against the file size, but does not validate the bucket contents it… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Hashmap SharedAI | 21/7/2026 | 22/7/2026 | Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts.… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Radixtree SharedAI | 21/7/2026 | 22/7/2026 | Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts.… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Sortedset SharedAI | 21/7/2026 | 22/7/2026 | Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow… | |
| Aplazada | Crítica (9.1) | 0.54% | — | Data Reqrep SharedAI | 21/7/2026 | 22/7/2026 | Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts.… | |
| Analizada | Alta (8.2) | 0.44% | — | Atlassian Confluence Data Center | 21/7/2026 | 11/8/2026 | This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive… | |
| Analizada | Alta (7.1) | 0.43% | — | Atlassian Confluence Data Center | 21/7/2026 | 10/8/2026 | This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable… | |
| Analizada | Alta (8.6) | 0.18% | — | Google MCP Toolbox FOR Databases | 21/7/2026 | 22/9/2026 | A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings and interpolates them unescaped via… | |
| Aplazada | Alta (7.3) | 0.34% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses against both the browser login flow and… | |
| Aplazada | Alta (7.3) | 0.34% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply `forwardToUrl` and `redirectUrl` values… | |
| Aplazada | Media (4.3) | 0.14% | — | Datacycle CoreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes server-side state changes through `GET` routes. Because browsers… | |
| Aplazada | Alta (8.1) | 0.35% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access token can ask the collection API to… | |
| Aplazada | Alta (7.5) | 0.89% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and static markdown renderer accepts attacker-controlled path segments… | |
| Aplazada | Media (4.3) | 0.27% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names and email addresses through… | |
| Aplazada | Alta (7.5) | 0.39% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary partials or helper-backed render functions… | |
| Aplazada | Media (6.1) | 0.27% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any unauthenticated attacker can place arbitrary HTML into flash notifications on public… | |
| Aplazada | Alta (7.5) | 0.39% | — | Datacycle-coreAI | 20/7/2026 | 21/7/2026 | dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached text file directly, even if the link is… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-goAI | 17/7/2026 | 23/7/2026 | Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-traceAI | 17/7/2026 | 23/7/2026 | dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on extraction. A… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog Dd-trace-pyAI | 17/7/2026 | 23/7/2026 | Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES limits on the extract path. A remote, unauthenticated attacker can send a… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Datadog NET TracerAI | 17/7/2026 | 17/7/2026 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on extraction, allowing a remote… | |
| Modificada | Media (5.4) | 0.39% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 17/7/2026 | 16/9/2026 | Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that… | |
| Modificada | Baja (2.7) | 0.35% | — | Redhat Build OF KeycloakRedhat Data GridRedhat Jboss Enterprise Application Platform Expansion PackRedhat Single Sign-on | 16/7/2026 | 16/9/2026 | A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching for a child group they have permission to… | |
| Pendiente de análisis | Alta (8.3) | 0.58% | — | Delphix Continous DataAI | 16/7/2026 | 16/7/2026 | A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter and lockout status were updated, defeating brute-force protections and enabling… | |
| Aplazada | Alta (7.1) | 0.56% | — | DataeaseAI | 15/7/2026 | 17/7/2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executing an SQL dataset path where CalciteProvider.jdbcFetchResultField… |