Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
–

1243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)1.3%—Heimdall Data Database ProxyAI20/8/20261/9/2026
Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaCrítica (9.1)0.45%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this…
AnalizadaMedia (5.3)0.32%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can…
ModificadaCrítica (9.6)0.40%—Oracle Database Server18/8/202622/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaCrítica (9.6)0.40%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaAlta (8.5)0.33%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,…
AplazadaAlta (7.4)0.43%—Xnau Participants DatabaseAI13/8/202614/8/2026
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
AnalizadaAlta (7.8)0.30%—Microsoft Azure SQL Database11/8/202617/8/2026
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (10)0.90%—Microsoft Azure SQL Database7/8/20268/8/2026
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (6.8)0.39%—Database FOR Contact Form 7 Wpforms Elementor FormsAI4/8/202626/8/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated…
AplazadaMedia (5.3)0.42%—Database Collation FIXAI1/8/202612/8/2026
The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
AplazadaCrítica (9.1)0.46%—Xnau Participants DatabaseAI1/8/202626/8/2026
The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.
AnalizadaAlta (8)0.25%—Google MCP Toolbox FOR Databases31/7/20268/8/2026
An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips…
AnalizadaAlta (8)0.13%—Google MCP Toolbox FOR Databases31/7/20268/8/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to…
AnalizadaMedia (6.6)0.24%—Google MCP Toolbox FOR Databases31/7/20268/8/2026
An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted…
AnalizadaMedia (5.7)0.20%—Google MCP Toolbox FOR Databases31/7/20268/8/2026
An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset…
AnalizadaAlta (8.1)0.25%—Google MCP Toolbox FOR Databases31/7/20268/8/2026
Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active.
Pendiente de análisisAlta (7.2)1.1%—Heimdall Data Database ProxyAI29/7/202630/7/2026
Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within…
AplazadaAlta (7.2)0.43%—Database FOR CF7AI29/7/202630/7/2026
The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (7.1)0.25%—Database FOR Contact Form 7 Wpforms Elementor FormsAI28/7/202628/7/2026
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (6)0.19%—Google MCP Toolbox FOR Databases27/7/202628/9/2026
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport…
AplazadaMedia (5.3)0.42%—Xnau Participants DatabaseAI24/7/202624/7/2026
The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing…
AplazadaAlta (7.1)0.25%—Form Vibes Database Manager FOR FormsAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.
AplazadaCrítica (10)0.60%—Xnau Participants DatabaseAI23/7/202623/7/2026
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
AplazadaCrítica (9.3)0.40%—Xnau Participants DatabaseAI23/7/202623/7/2026
Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.