Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

5057 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.40%—WpdatatablesAI26/6/202626/6/2026
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
AnalizadaMedia (6.5)0.35%—Fasterxml Jackson-databind23/6/202627/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The…
AnalizadaMedia (5.3)0.38%—Fasterxml Jackson-databind23/6/202627/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch…
AnalizadaMedia (5.3)0.45%—Fasterxml Jackson-databind23/6/202627/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be renamed rather than…
AnalizadaMedia (5.3)0.44%💥 PoCFasterxml Jackson-databind23/6/202629/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual…
AnalizadaMedia (5.3)0.37%—Fasterxml Jackson-databind23/6/202627/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at…
ModificadaAlta (8.1)1.2%—Fasterxml Jackson-databind23/6/202614/9/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's…
AnalizadaAlta (8.1)1.00%💥 PoCFasterxml Jackson-databind23/6/202627/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and…
AnalizadaMedia (6.3)0.62%—Fasterxml Jackson-databind23/6/202627/6/2026
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends deeply nested JSON if (and only if) the service reads deeply nested (1000s of levels) JSON as JsonNode…
AnalizadaMedia (5.3)0.26%—IBM DatacapIBM Datacap Navigator22/6/202626/6/2026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by directly requesting the URL, bypassing intended access controls.
AnalizadaAlta (7.5)0.20%—IBM DatacapIBM Datacap Navigator22/6/202626/6/2026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Attacker can use the same keys to decrypt password, gain access to the application and access sensitive data in the database.
AnalizadaMedia (6.1)0.24%—IBM DatacapIBM Datacap Navigator22/6/202626/6/2026
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
ModificadaAlta (7.7)0.44%—Grafana Loki Datasource22/6/202610/7/2026
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
AplazadaAlta (8.1)1.0%—Database FOR Contact Form 7 Wpforms Elementor FormsAI20/6/202622/6/2026
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the…
AnalizadaAlta (8.8)0.49%—Joomshaper Standard PRO Movie Database19/6/202619/8/2026
Joomla SP Movie Database 1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the searchword parameter. Attackers can send GET requests to the searchresults view with crafted SQL payloads in the searchword parameter to…
AnalizadaAlta (8.6)0.14%—Google MCP Toolbox FOR Databases18/6/202617/8/2026
An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18,…
AnalizadaCrítica (9.3)0.18%—Google MCP Toolbox FOR Databases18/6/202617/8/2026
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent…
AnalizadaCrítica (9.3)0.18%—Google MCP Toolbox FOR Databases18/6/202617/8/2026
An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is…
AplazadaCrítica (9.3)0.40%—WpdatatablesAI17/6/202617/6/2026
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
Pendiente de análisisMedia (5.6)0.28%—Gnome Evolution-data-serverAI17/6/202625/9/2026
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during…
AnalizadaAlta (8.3)0.39%—Oracle Data Integrator17/6/202618/6/2026
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful…
AplazadaCrítica (9.3)0.40%—Wpdataaccess WP Data AccessAI15/6/202617/6/2026
Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.
AplazadaCrítica (9.8)0.54%—Datalogics Ecommerce DeliveryAI15/6/202617/6/2026
Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.
AplazadaMedia (6.5)0.41%—Datadog VectorAI15/6/202617/6/2026
An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.
AplazadaCrítica (9.8)0.47%—Datadog VectorAI15/6/202617/6/2026
Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive database information via crafted SQL statements.