Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.21% | — | BudibaseAI | 26/9/2026 | 30/9/2026 | Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in… | |
| Aplazada | Alta (8.3) | 0.21% | — | BudibaseAI | 26/9/2026 | 30/9/2026 | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and… | |
| Aplazada | Crítica (9.2) | 0.33% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and… | |
| Aplazada | Alta (8.9) | 0.21% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier /… | |
| Aplazada | Alta (8.7) | 0.57% | — | Budibase ServerAI | 26/9/2026 | 30/9/2026 | Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary… | |
| Aplazada | Media (6.3) | 0.25% | — | BudibaseAI | 26/9/2026 | 30/9/2026 | Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. Attackers can submit a crafted POST request to inject an attacker-controlled… | |
| Aplazada | Alta (8.6) | 0.23% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validator, allowing authenticated builders to read arbitrary local files. Attackers with builder access can embed file:// references in OpenAPI specifications submitted to the import endpoint to exfiltrate… | |
| Pendiente de análisis | Media (5.3) | 0.33% | — | Wikimedia WikibaseAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Baja (2) | 0.19% | — | Huanzi-qch Base-adminAI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affects the function Save of the file base-admin-master\src\main\java\cn\huanzi\qch\baseadmin\common\controller\CommonController.java of the component Add User Handler. The manipulation of the argument… | |
| Aplazada | Crítica (9.1) | 0.51% | — | DatabasementAI | 22/9/2026 | 23/9/2026 | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user… | |
| Aplazada | Media (6.5) | 0.40% | — | NocobaseAI | 21/9/2026 | 22/9/2026 | A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request. | |
| Aplazada | Crítica (9.8) | 0.47% | — | NocobaseAI | 21/9/2026 | 22/9/2026 | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements. | |
| Aplazada | Media (6.5) | 0.45% | — | Supabase RealtimeAI | 21/9/2026 | 24/9/2026 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel client is allowed presence.write but explicitly denied presence.read. Under that… | |
| Aplazada | Baja (2.1) | 0.45% | — | DLR Stable-baselines3AIPytorchAI | 20/9/2026 | 21/9/2026 | A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Pendiente de análisis | Media (6.9) | 0.47% | — | MetabaseAI | 16/9/2026 | 22/9/2026 | Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers. | |
| Aplazada | Alta (8.8) | 0.52% | — | Next-tinacms-azureAISupabase AuthAI | 16/9/2026 | 30/9/2026 | Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any… | |
| Aplazada | Alta (8.7) | 0.58% | — | PocketbaseAI | 16/9/2026 | 30/9/2026 | Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal goroutines can escape recovery and terminate the server process, causing a denial of… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS.… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Database ServerAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Database ServerAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create DB Link privilege with network access via Oracle Net to compromise RDBMS. Successful attacks… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Database ServerAIOracle NET ServicesAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can… | |
| Aplazada | Alta (8.5) | 0.32% | — | Oracle Database ServerAIOracle TextAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Create Index privilege with network access via Oracle Net to compromise Oracle Text. While… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise RDBMS.… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can… |