Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2769 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.2) | 0.24% | — | Basecamp Google Sign INAIRubyonrails RailsAI | 27/8/2025 | 17/6/2026 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a malformed URL that passes the "same origin" check, resulting in the user being redirected to another origin. Rails applications configured to store the flash information in a session cookie may be… | |
| Modificada | Crítica (9.1) | 0.53% | — | Browserify Cipher-base | 20/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Genx FXAIGoogle CloudAIGoogle FirebaseAIGithubAI | 19/8/2025 | 17/6/2026 | GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud, Firebase, GitHub,… | |
| Aplazada | Media (5.4) | 0.14% | — | Pl4g4 Wp-database-optimizer-toolsAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.This issue affects WP-Database-Optimizer-Tools: from n/a through <= 0.2. | |
| Aplazada | Crítica (10) | 0.65% | — | Hyland OnbaseAI | 13/8/2025 | 17/6/2026 | Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code execution via insecure deserialization on the .NET Remoting TCP channel. The service registers a listener on port 6031 with the URI endpoint TimerServer, implemented in Hyland.Core.Timers.dll. This… | |
| Aplazada | Crítica (9.8) | 1.3% | 💥 PoC | Database FOR Contact Form 7AIWpformsAIElementor FormsAI | 13/8/2025 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.3 via deserialization of untrusted input in the get_lead_detail function. This makes it possible for unauthenticated attackers to inject a PHP Object. The… | |
| Analizada | Media (6.4) | 0.19% | — | Solarwinds Database Performance Analyzer | 12/8/2025 | 17/6/2026 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level… | |
| Modificada | Media (6.5) | 0.14% | — | Google Firebase Php-jwt | 31/7/2025 | 17/6/2026 | php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an… | |
| Analizada | Alta (7.3) | 0.19% | — | Couchbase Sync Gateway | 29/7/2025 | 17/6/2026 | An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in redacted and unredacted output. | |
| Analizada | Crítica (9.8) | 21% | 💥 Exploit | Wpseeds WP Database Backup | 25/7/2025 | 17/6/2026 | The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system. | |
| Aplazada | Media (6.3) | 0.33% | — | OceanbaseAI | 24/7/2025 | 17/6/2026 | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. This vulnerability only affects OceanBase tenants in Oracle mode. Tenants in MySQL mode are unaffected. | |
| Aplazada | Media (4.4) | 0.26% | 💥 PoC | Knowledge BaseAI | 18/7/2025 | 17/6/2026 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all versions up to, and including, 2.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Aplazada | Alta (8.5) | 0.29% | — | Quanticalabs Gymbase Theme ClassesAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBase Theme Classes gymbase_classes allows SQL Injection.This issue affects GymBase Theme Classes: from n/a through <= 1.4. | |
| Analizada | Media (5.3) | 0.13% | — | Oracle Database Server | 15/7/2025 | 17/6/2026 | Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Authenticated OS User privilege with logon to the infrastructure where JDBC executes to compromise JDBC. Successful attacks require… | |
| Analizada | Baja (2.7) | 0.28% | — | Oracle Database Server | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to… | |
| Modificada | Alta (8.8) | 0.38% | — | Oracle Database Server | 15/7/2025 | 17/6/2026 | Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database.… | |
| Analizada | Baja (2.4) | 0.25% | — | Oracle Database Server | 15/7/2025 | 17/6/2026 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with network access via Oracle Net to compromise Unified Audit. Successful… | |
| Aplazada | Baja (2) | 0.27% | — | Bigotry OnebaseAI | 14/7/2025 | 17/6/2026 | A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerability is the function parse_args of the file /tpl/think_exception.tpl. The manipulation of the argument args leads to cross site scripting. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.31% | — | Ciphercoin Contact Form 7 Database Addon | 4/7/2025 | 17/6/2026 | The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ parameter in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (4.3) | 0.15% | — | Skywavesolutions WP Firebase Push Notification | 4/7/2025 | 17/6/2026 | The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. This makes it possible for unauthenticated attackers to send… | |
| Aplazada | Baja (2) | 0.54% | — | Nokia Single RAN Baseband SoftwareAI | 2/7/2025 | 17/6/2026 | Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service. No practical exploit has been detected for this flaw. However, the issue has been… | |
| Aplazada | Baja (3.3) | 0.14% | — | Nokia Single RAN Baseband SoftwareAI | 2/7/2025 | 17/6/2026 | The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release version by sending a specific HTTP POST request through the Mobile Network Operator (MNO) internal RAN management network. | |
| Aplazada | Media (6.4) | 0.18% | — | Nokia Single RAN Baseband SoftwareAI | 2/7/2025 | 17/6/2026 | Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal… | |
| Aplazada | Alta (7.1) | 0.21% | — | Nokia Single RAN Airscale BasebandAI | 2/7/2025 | 17/6/2026 | Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The baseband does not re-authenticate the user when they connect from the baseband system board to the baseband capacity boards using the internal… | |
| Aplazada | Alta (7.1) | 0.13% | — | Devfelixmoira Knowledge Base MakerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in devfelixmoira Knowledge Base – Knowledge Base Maker knowledge-base-maker allows Stored XSS.This issue affects Knowledge Base – Knowledge Base Maker: from n/a through <= 1.1.8. |