Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 1.3% | — | Heimdall Data Database ProxyAI | 20/8/2026 | 1/9/2026 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this… | |
| Analizada | Media (5.3) | 0.32% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can… | |
| Modificada | Crítica (9.6) | 0.40% | — | Oracle Database Server | 18/8/2026 | 22/8/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Crítica (9.6) | 0.40% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Database Server | 18/8/2026 | 20/8/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,… | |
| Aplazada | Alta (7.4) | 0.43% | — | Xnau Participants DatabaseAI | 13/8/2026 | 14/8/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure SQL Database | 11/8/2026 | 17/8/2026 | Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure SQL Database | 7/8/2026 | 8/8/2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Aplazada | Media (5.3) | 0.42% | — | Database Collation FIXAI | 1/8/2026 | 12/8/2026 | The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Xnau Participants DatabaseAI | 1/8/2026 | 26/8/2026 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Analizada | Alta (8) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips… | |
| Analizada | Alta (8) | 0.13% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to… | |
| Analizada | Media (6.6) | 0.24% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted… | |
| Analizada | Media (5.7) | 0.20% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset… | |
| Analizada | Alta (8.1) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active. | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Heimdall Data Database ProxyAI | 29/7/2026 | 30/7/2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Aplazada | Alta (7.2) | 0.43% | — | Database FOR CF7AI | 29/7/2026 | 30/7/2026 | The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.1) | 0.25% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/7/2026 | 28/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6) | 0.19% | — | Google MCP Toolbox FOR Databases | 27/7/2026 | 28/9/2026 | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport… | |
| Aplazada | Media (5.3) | 0.42% | — | Xnau Participants DatabaseAI | 24/7/2026 | 24/7/2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing… | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Aplazada | Crítica (10) | 0.60% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. |