Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
5073 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.22% | — | Datahub | 14/5/2026 | 17/6/2026 | DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data… | |
| Aplazada | Alta (7.5) | 0.57% | — | Database Backup FOR WordpressAI | 14/5/2026 | 17/6/2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated… | |
| Aplazada | Alta (8.1) | 0.57% | — | Database Backup FOR WordpressAI | 14/5/2026 | 17/6/2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter.… | |
| Aplazada | Alta (7.5) | 0.50% | — | Deliciousbrains Database BackupAI | 14/5/2026 | 17/6/2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables,… | |
| Analizada | Alta (7.2) | 0.34% | — | Hitachi Vantara Pentaho Data Integration AND Analytics | 13/5/2026 | 7/10/2026 | Hitachi Vantara Pentaho Data Integration & Analytics de todas las versiones contienen un controlador JDBC para bases de datos H2 que es vulnerable a la ejecución de scripts externos cuando un administrador de fuente de datos crea una nueva conexión. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Data Formulator | 12/5/2026 | 17/6/2026 | Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially… | |
| Pendiente de análisis | Crítica (9.3) | 0.13% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may… | |
| Pendiente de análisis | Alta (8.3) | 0.12% | — | Intel Data Center Graphics DriverAIVmware EsxiAI | 12/5/2026 | 17/6/2026 | Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur… | |
| Aplazada | Media (4.9) | 0.29% | — | Wpsemplugins WP SEO Structured Data SchemaAI | 12/5/2026 | 17/6/2026 | The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (6.5) | 0.48% | — | Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI | 11/5/2026 | 17/6/2026 | kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were… | |
| Analizada | Media (5.3) | 0.18% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | Una vulnerabilidad de falta de autorización en HCL BigFix WebUI permite a un usuario autenticado sin los permisos adecuados ver información ambiental sensible mediante acceso directo a la URL de la página no autorizada. | |
| Analizada | Media (5.3) | 0.22% | — | Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+17 | 9/5/2026 | 25/7/2026 | Una vulnerabilidad de autorización impropia en HCL BigFix WebUI permite a un usuario autenticado sin privilegios de Operador Maestro acceder a datos internos (nombres de sitios, versiones y variables de configuración) y eludir los requisitos de privilegios a través de puntos finales desprotegidos que carecen de… | |
| Aplazada | Crítica (10) | 0.42% | — | Data Space PortalAI | 8/5/2026 | 17/6/2026 | Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered "PENDING" organization / user accounts. This issue has been… | |
| Pendiente de análisis | Crítica (9.3) | 0.20% | — | 3onedata Modbus Gateway Gw1101-1dAI | 4/5/2026 | 7/10/2026 | El dispositivo gateway Modbus 3onedata modelo GW1101-1D(RS-485)-TB-P (versión de hardware V2.2.0) permite a usuarios autenticados ejecutar comandos shell arbitrarios en el contexto del usuario root al proporcionar payload en el campo de la 'dirección IP' de las herramientas de prueba de diagnóstico. Este problema ha… | |
| Aplazada | Media (6.9) | 0.41% | — | Shandong Hoteam Software PDM Product Data Management SystemAI | 4/5/2026 | 17/6/2026 | A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely.… | |
| En análisis | Media (5.5) | 0.09% | — | IBM Watsonx.data | 30/4/2026 | 7/10/2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 almacena credenciales de usuario en texto sin cifrar que pueden ser leídas por un usuario local. | |
| Analizada | Alta (7.5) | 0.19% | — | IBM Watsonx.data | 30/4/2026 | 7/10/2026 | IBM watsonx.data 2.2 a 2.3 IBM Lakehouse no restringe adecuadamente la comunicación entre pods, lo que podría permitir a un atacante transferir datos entre pods sin restricciones. | |
| Aplazada | Media (5.5) | 0.63% | — | Geldata Gel-mcpAI | 29/4/2026 | 17/6/2026 | A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in path traversal. The attack may be performed from remote. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.59% | — | Eghuzefa Engineer-your-dataAI | 28/4/2026 | 24/7/2026 | Una vulnerabilidad fue identificada en eghuzefa engineer-your-data hasta la versión 0.1.3. Esta vulnerabilidad afecta a la función read_file/write_file/list_files/file_inf del archivo src/server.py. La manipulación del argumento WORKSPACE_PATH conduce a un salto de ruta. El ataque puede ser iniciado remotamente. El… | |
| Aplazada | Media (5.5) | 0.51% | — | Alejandroarciniegas Mcp-data-visAI | 27/4/2026 | 17/6/2026 | A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-side request… | |
| Aplazada | Alta (8.8) | 0.24% | 💥 PoC | Diskoverdata Diskover-communityAI | 27/4/2026 | 5/7/2026 | Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php | |
| Aplazada | Media (5.3) | 0.41% | — | Baomidou Dynamic-datasourceAI | 26/4/2026 | 17/6/2026 | A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the component… | |
| Aplazada | Baja (2.9) | 0.43% | — | Datavane DatavinesAI | 26/4/2026 | 17/6/2026 | A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argument tokenSecret… |