Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

5073 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.22%—Datahub14/5/202617/6/2026
DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization of Untrusted Data…
AplazadaAlta (7.5)0.57%—Database Backup FOR WordpressAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to the plugin not restricting access to the wp_db_temp_dir parameter, which controls where database backups are written. This makes it possible for unauthenticated…
AplazadaAlta (8.1)0.57%—Database Backup FOR WordpressAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check combined with a user-controlled backup directory parameter.…
AplazadaAlta (7.5)0.50%—Deliciousbrains Database BackupAI14/5/202617/6/2026
The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due to the plugin not properly enforcing the return value of its authorization check. This makes it possible for unauthenticated attackers to export database tables,…
AnalizadaAlta (7.2)0.34%—Hitachi Vantara Pentaho Data Integration AND Analytics13/5/20267/10/2026
Hitachi Vantara Pentaho Data Integration & Analytics de todas las versiones contienen un controlador JDBC para bases de datos H2 que es vulnerable a la ejecución de scripts externos cuando un administrador de fuente de datos crea una nueva conexión.
AnalizadaAlta (8.8)0.86%—Microsoft Data Formulator12/5/202617/6/2026
Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds write for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data corruption. This result may potentially…
Pendiente de análisisCrítica (9.3)0.13%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may…
Pendiente de análisisAlta (8.3)0.12%—Intel Data Center Graphics DriverAIVmware EsxiAI12/5/202617/6/2026
Out-of-bounds read for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur…
AplazadaMedia (4.9)0.29%—Wpsemplugins WP SEO Structured Data SchemaAI12/5/202617/6/2026
The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `_kcseo_ative_tab` parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaMedia (6.5)0.48%—Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI11/5/202617/6/2026
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were…
AnalizadaMedia (5.3)0.18%—Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+179/5/202625/7/2026
Una vulnerabilidad de falta de autorización en HCL BigFix WebUI permite a un usuario autenticado sin los permisos adecuados ver información ambiental sensible mediante acceso directo a la URL de la página no autorizada.
AnalizadaMedia (5.3)0.22%—Hcltech Bigfix Webui APIHcltech Bigfix Webui Application AdministrationHcltech Bigfix Webui CmepHcltech Bigfix Webui Common+179/5/202625/7/2026
Una vulnerabilidad de autorización impropia en HCL BigFix WebUI permite a un usuario autenticado sin privilegios de Operador Maestro acceder a datos internos (nombres de sitios, versiones y variables de configuración) y eludir los requisitos de privilegios a través de puntos finales desprotegidos que carecen de…
AplazadaCrítica (10)0.42%—Data Space PortalAI8/5/202617/6/2026
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insufficient authorization in the dataspace-portal backend regarding self-registered "PENDING" organization / user accounts. This issue has been…
Pendiente de análisisCrítica (9.3)0.20%—3onedata Modbus Gateway Gw1101-1dAI4/5/20267/10/2026
El dispositivo gateway Modbus 3onedata modelo GW1101-1D(RS-485)-TB-P (versión de hardware V2.2.0) permite a usuarios autenticados ejecutar comandos shell arbitrarios en el contexto del usuario root al proporcionar payload en el campo de la 'dirección IP' de las herramientas de prueba de diagnóstico. Este problema ha…
AplazadaMedia (6.9)0.41%—Shandong Hoteam Software PDM Product Data Management SystemAI4/5/202617/6/2026
A vulnerability was determined in Shandong Hoteam Software PDM Product Data Management System up to 8.3.9. This affects the function GetQueryMachineGridOnePageData of the file /Base/BaseService.asmx/DataService. This manipulation of the argument SortOrder causes sql injection. The attack can be initiated remotely.…
En análisisMedia (5.5)0.09%—IBM Watsonx.data30/4/20267/10/2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.3.0, 5.3.1 almacena credenciales de usuario en texto sin cifrar que pueden ser leídas por un usuario local.
AnalizadaAlta (7.5)0.19%—IBM Watsonx.data30/4/20267/10/2026
IBM watsonx.data 2.2 a 2.3 IBM Lakehouse no restringe adecuadamente la comunicación entre pods, lo que podría permitir a un atacante transferir datos entre pods sin restricciones.
AplazadaMedia (5.5)0.63%—Geldata Gel-mcpAI29/4/202617/6/2026
A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in path traversal. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaMedia (5.5)0.59%—Eghuzefa Engineer-your-dataAI28/4/202624/7/2026
Una vulnerabilidad fue identificada en eghuzefa engineer-your-data hasta la versión 0.1.3. Esta vulnerabilidad afecta a la función read_file/write_file/list_files/file_inf del archivo src/server.py. La manipulación del argumento WORKSPACE_PATH conduce a un salto de ruta. El ataque puede ser iniciado remotamente. El…
AplazadaMedia (5.5)0.51%—Alejandroarciniegas Mcp-data-visAI27/4/202617/6/2026
A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d. Affected by this vulnerability is the function axios of the file src/servers/web-scraper/server.js of the component HTTP Request Handler. Such manipulation leads to server-side request…
AplazadaAlta (8.8)0.24%💥 PoCDiskoverdata Diskover-communityAI27/4/20265/7/2026
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
AplazadaMedia (5.3)0.41%—Baomidou Dynamic-datasourceAI26/4/202617/6/2026
A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the component…
AplazadaBaja (2.9)0.43%—Datavane DatavinesAI26/4/202617/6/2026
A vulnerability was determined in Datavane Datavines up to 13607645e14a4982468cfdbcf75c85cde63bae71. The affected element is an unknown function of the file datavines-core/src/main/java/io/datavines/core/utils/TokenManager.java of the component JWT Token Handler. Executing a manipulation of the argument tokenSecret…