Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.46% | — | ArcadedbAI | 18/8/2026 | 8/9/2026 | ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users to read local files. Attackers with read query privileges can use the file:// protocol in LOAD CSV statements to access arbitrary files with server process privileges,… | |
| Aplazada | Media (5.3) | 0.37% | — | ArcadedbAI | 18/8/2026 | 8/9/2026 | ArcadeDB before 26.8.1 contains a denial of service vulnerability in the Cypher range() function that allows authenticated users to exhaust server heap memory. Attackers can submit oversized range() expressions with large bounds to trigger OutOfMemoryError and cause temporary service degradation or unavailability. | |
| Aplazada | Alta (8.7) | 0.43% | — | ArcadedbAIOracle GraalvmAI | 18/8/2026 | 8/9/2026 | ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped regular expressions to validate package names. Attackers with trigger creation privileges can use Java.type() to access java.util.zip.ZipFile or java.util.jar.JarFile… | |
| Aplazada | Media (5.3) | 0.31% | — | Arcadedb-serverAI | 18/8/2026 | 31/8/2026 | ArcadeDB (com.arcadedb:arcadedb-server) versions <= 26.7.3 contain an insecure direct object reference (IDOR) vulnerability in the Raft cluster-info endpoints (GetClusterHandler and PostBootstrapStateHandler), which authenticate but do not authorize access. On an ArcadeDB HA cluster (only reachable when… | |
| Aplazada | Alta (7.1) | 0.47% | — | CratedbAI | 14/8/2026 | 18/9/2026 | CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob storage: SQL (`SELECT ... FROM blob.<table>`… | |
| Analizada | Alta (7.1) | 0.44% | — | Timescaledb | 6/8/2026 | 1/9/2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and… | |
| Analizada | Alta (7.2) | 0.53% | — | Timescaledb | 6/8/2026 | 1/9/2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit… | |
| Analizada | Alta (7.1) | 0.51% | — | Timescaledb | 6/8/2026 | 1/9/2026 | TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compressed datum with an internally inconsistent BitArray. Attackers with DML access to… | |
| Aplazada | Alta (7.1) | 0.32% | — | MagistralaAIPostgresqlAITimescaledbAI | 5/8/2026 | 26/8/2026 | Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf in both the PostgreSQL reader (readers/postgres/messages.go: ) and the TimescaleDB reader… | |
| Aplazada | Alta (7.7) | 0.36% | — | ArcadedbAI | 2/8/2026 | 31/8/2026 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary JavaScript code via the query tool. | |
| Aplazada | Alta (7.7) | 0.42% | — | ArcadedbAI | 2/8/2026 | 31/8/2026 | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to… | |
| Aplazada | Alta (8.7) | 0.44% | — | ArcadedbAI | 2/8/2026 | 31/8/2026 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute JavaScript to create server-wide admin users,… | |
| Aplazada | Alta (8.5) | 0.24% | — | ArcadedbAI | 1/8/2026 | 31/8/2026 | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map to setCustomValue and setBucketSelectionStrategy in LocalDocumentType. An authenticated user with only read access (e.g., a read-only API… | |
| Aplazada | Alta (8.7) | 0.51% | — | ArcadedbAI | 1/8/2026 | 31/8/2026 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate… | |
| Aplazada | Crítica (9.3) | 0.54% | — | ArcadedbAI | 1/8/2026 | 31/8/2026 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases they are not authorized to use by directly calling affected endpoints… | |
| Aplazada | Crítica (9.3) | 0.54% | — | ArcadedbAI | 1/8/2026 | 31/8/2026 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, bypassing security controls intended to restrict scripting to… | |
| Aplazada | Alta (8.6) | 0.92% | — | Arcadedb-engineAI | 1/8/2026 | 8/9/2026 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can create a JavaScript trigger that invokes… | |
| Analizada | Alta (7.7) | 0.51% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation, including by a low-privileged user able to… | |
| Analizada | Crítica (9) | 0.40% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default… | |
| Analizada | Crítica (9) | 0.41% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can… | |
| Analizada | Media (6.1) | 0.38% | — | Enterprisedb Pglogical | 28/7/2026 | 24/8/2026 | pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. A party acting as the publisher for a subscription, for example a non-PostgreSQL endpoint that speaks the pglogical replication… | |
| Aplazada | Baja (1.3) | 0.33% | — | Unitedbyai DroidclawAI | 27/7/2026 | 28/7/2026 | A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/routes/goals.ts of the component Unsigned Scheduled Callback. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The attack is… | |
| Aplazada | Alta (8.7) | 0.51% | — | FeedbinAI | 21/7/2026 | 23/7/2026 | Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer… | |
| Analizada | Baja (3.1) | 0.21% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Incorrect Authorization vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Forceful Browsing. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. | |
| Analizada | Media (6.1) | 0.25% | — | Anuaralfetahe Advanced Content Feedback | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Advanced Content Feedback (aka admin_feedback) allows Stored XSS. This issue affects Advanced Content Feedback (aka admin_feedback) versions: from 0.0.0 to 2.8.0. |