Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
5042 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.36% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 podría permitir a un usuario autenticado eludir los controles de seguridad y realizar acciones no autorizadas debido a la aplicación del lado del cliente de la seguridad del lado del servidor. | |
| Analizada | Media (4.3) | 0.27% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a la falsificación de petición del lado del servidor (SSRF). Esto podría permitir a un atacante autenticado enviar peticiones no autorizadas desde el sistema, lo que podría llevar a la enumeración de la red o facilitar otros ataques. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría llevar a la divulgación de credenciales dentro… | |
| Analizada | Media (5.7) | 0.41% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a inyección HTML. Un atacante remoto podría inyectar código HTML malicioso que, al ser visto, sería ejecutado en el navegador web de la víctima dentro del contexto de seguridad del sitio anfitrión. | |
| Analizada | Media (6.4) | 0.26% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 es vulnerable a cross-site scripting almacenado. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista y lo que podría llevar a la divulgación de… | |
| Analizada | Media (4.3) | 0.43% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 podría permitir a un usuario autenticado causar una denegación temporal utilizando una solicitud HTTP especialmente diseñada debido a una asignación incorrecta de la limitación de recursos. | |
| Modificada | Media (5.9) | 0.20% | — | IBM Watsonx.data Intelligence | 30/6/2026 | 29/9/2026 | IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 hasta el parche-1 transmite datos en texto claro que podría permitir a un atacante obtener información sensible utilizando técnicas de man in the middle. | |
| Aplazada | Alta (8) | 0.62% | — | Export User DataAI | 30/6/2026 | 30/6/2026 | The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize function in all versions up to, and including, 2.2.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on… | |
| Analizada | Crítica (9.3) | 0.53% | — | Google MCP Toolbox FOR Databases | 29/6/2026 | 1/7/2026 | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool path and parses the resulting string as a relative URL. While it checks that the input does not alter… | |
| Aplazada | Baja (2.1) | 0.38% | — | DatabendAI | 28/6/2026 | 30/6/2026 | A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_manager.rs of the component Tenant Handler. The manipulation leads to authorization bypass. It is possible to initiate the… | |
| Aplazada | Crítica (9.3) | 0.40% | — | WpdatatablesAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. | |
| Analizada | Media (6.5) | 0.35% | — | Fasterxml Jackson-databind | 23/6/2026 | 27/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The… | |
| Analizada | Media (5.3) | 0.38% | — | Fasterxml Jackson-databind | 23/6/2026 | 27/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch… | |
| Analizada | Media (5.3) | 0.45% | — | Fasterxml Jackson-databind | 23/6/2026 | 27/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be renamed rather than… | |
| Analizada | Media (5.3) | 0.44% | 💥 PoC | Fasterxml Jackson-databind | 23/6/2026 | 29/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual… | |
| Analizada | Media (5.3) | 0.37% | — | Fasterxml Jackson-databind | 23/6/2026 | 27/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at… | |
| Modificada | Alta (8.1) | 1.2% | — | Fasterxml Jackson-databind | 23/6/2026 | 14/9/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's… | |
| Analizada | Alta (8.1) | 1.00% | 💥 PoC | Fasterxml Jackson-databind | 23/6/2026 | 27/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and… | |
| Analizada | Media (6.3) | 0.62% | — | Fasterxml Jackson-databind | 23/6/2026 | 27/6/2026 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode… | |
| Analizada | Media (5.3) | 0.26% | — | IBM DatacapIBM Datacap Navigator | 22/6/2026 | 26/6/2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls. | |
| Analizada | Alta (7.5) | 0.20% | — | IBM DatacapIBM Datacap Navigator | 22/6/2026 | 26/6/2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database. | |
| Analizada | Media (6.1) | 0.24% | — | IBM DatacapIBM Datacap Navigator | 22/6/2026 | 26/6/2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Modificada | Alta (7.7) | 0.44% | — | Grafana Loki Datasource | 22/6/2026 | 10/7/2026 | A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information. | |
| Aplazada | Alta (8.1) | 1.0% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 20/6/2026 | 22/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomshaper Standard PRO Movie Database | 19/6/2026 | 19/8/2026 | Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to… |