Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
5032 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.4) | 0.17% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('Link following') vulnerability. A high privileged… | |
| Analizada | Media (5.8) | 0.11% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with… | |
| Analizada | Media (4.4) | 0.17% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper link resolution before file access ('link following') vulnerability. A high privileged… | |
| Analizada | Media (4.4) | 0.15% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect permission Assignment for critical resource vulnerability. A high privileged attacker… | |
| Analizada | Media (4.4) | 0.17% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A… | |
| Analizada | Media (4.3) | 0.25% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper access control vulnerability in the RBAC. A low privileged attacker with remote access… | |
| Analizada | Media (6.5) | 1.8% | — | Dell Data Domain Operating System | 3/7/2026 | 8/7/2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection')… | |
| Analizada | Alta (7) | 0.66% | — | Juicedata Juicefs | 2/7/2026 | 17/8/2026 | JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline… | |
| Analizada | Media (5.1) | 0.43% | — | Netdata | 2/7/2026 | 5/10/2026 | Netdata anterior a 2.3.1 refleja el parámetro de consulta 'love' proporcionado por el usuario de los endpoints API/v2/ilove.svg y API/v3/ilove.svg textualmente en el documento SVG generado (en un elemento de texto) sin escape HTML o XML, y sirve la respuesta con Content-Type image/svg+xml. Un atacante puede crear una… | |
| Aplazada | Alta (7.1) | 0.25% | — | WpdatatablesAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in wpDataTables <= 6.5.1.1 versions. | |
| Aplazada | Alta (7.2) | 2.7% | — | Wpseeds WP Database BackupAI | 2/7/2026 | 2/7/2026 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into… | |
| Pendiente de análisis | Media (5.6) | 0.39% | — | Solarwinds Database Performance AnalyzerAI | 30/6/2026 | 2/7/2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmite datos en texto claro que podría permitir a un atacante obtener información sensible utilizando técnicas de man in the middle. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 podría permitir a un usuario autenticado realizar acciones no autorizadas debido a la aplicación incorrecta del flujo de trabajo de comportamiento. | |
| Analizada | Media (4.3) | 0.37% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 podría permitir a un atacante remoto obtener información sensible cuando se devuelve un mensaje de error técnico detallado en el navegador. Esta información podría utilizarse en ataques posteriores contra el sistema. | |
| Analizada | Media (6.5) | 0.36% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 podría permitir a un usuario autenticado eludir los controles de seguridad y realizar acciones no autorizadas debido a la aplicación del lado del cliente de la seguridad del lado del servidor. | |
| Analizada | Media (4.3) | 0.27% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a la falsificación de petición del lado del servidor (SSRF). Esto podría permitir a un atacante autenticado enviar peticiones no autorizadas desde el sistema, lo que podría llevar a la enumeración de la red o facilitar otros ataques. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría llevar a la divulgación de credenciales dentro… | |
| Analizada | Media (5.7) | 0.41% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a inyección HTML. Un atacante remoto podría inyectar código HTML malicioso que, al ser visto, sería ejecutado en el navegador web de la víctima dentro del contexto de seguridad del sitio anfitrión. | |
| Analizada | Media (6.4) | 0.26% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a cross-site scripting almacenado. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista y lo que podría llevar a la divulgación de… | |
| Analizada | Media (4.3) | 0.43% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 podría permitir a un usuario autenticado causar una denegación temporal utilizando una solicitud HTTP especialmente diseñada debido a una asignación incorrecta de la limitación de recursos. | |
| Modificada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 hasta el parche-1 transmite datos en texto claro que podría permitir a un atacante obtener información sensible utilizando técnicas de man in the middle. | |
| Aplazada | Alta (8) | 0.62% | — | Export User DataAI | 30/6/2026 | 30/6/2026 | The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on… | |
| Analizada | Crítica (9.3) | 0.53% | — | Google MCP Toolbox FOR Databases | 29/6/2026 | 1/7/2026 | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter… | |
| Aplazada | Baja (2.1) | 0.38% | — | DatabendAI | 28/6/2026 | 30/6/2026 | A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the… |