Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2768 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.32%—Oracle Database ServerAIOracle XML Developers KITAI15/9/202617/9/2026
Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML…
Pendiente de análisisAlta (7.7)0.37%—Oracle Database ServerAI15/9/202616/9/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,…
Pendiente de análisisAlta (7.7)0.34%—Oracle Enterprise ManagerAIOracle DatabaseAI15/9/202616/9/2026
Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle…
Pendiente de análisisMedia (6.5)0.30%—Oracle Enterprise Manager Base PlatformAI15/9/202616/9/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Enterprise Manager…
Pendiente de análisisAlta (8.1)0.35%—Oracle E-business SuiteAIOracle Installed BaseAI15/9/202618/9/2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks…
AplazadaMedia (6.5)0.36%—Oracle Database ServerAI15/9/202618/9/2026
Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Net Services. Successful attacks require human interaction from a…
AplazadaMedia (4.4)0.19%—Outerbase StudioAI15/9/202630/9/2026
Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to…
AplazadaMedia (6.4)0.55%—DobaseAI11/9/202630/9/2026
Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthenticated shared-folder image gallery. A file's `name` is fully attacker-controlled and is never sanitized. It is…
AplazadaCrítica (9.3)0.37%—CapgoAISupabaseAISupabase PostgrestAI10/9/202630/9/2026
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route…
AplazadaAlta (8.7)0.52%💥 PoCCapgoAISupabaseAI10/9/202630/9/2026
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been…
AplazadaMedia (6.9)0.61%—Ragic Enterprise Cloud DatabaseAI9/9/20269/9/2026
The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.
AplazadaAlta (7.1)0.39%—QtbaseAIQtxmlAI8/9/202611/9/2026
Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no configurable bound and no error return. A…
Pendiente de análisisAlta (8.4)0.48%💥 PoC389 Project 389 DS BaseAICockpit 389 ConsoleAI7/9/20268/9/2026
A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN…
AplazadaAlta (7.1)0.43%—MetabaseAI5/9/202624/9/2026
Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries. Attackers can submit requests to POST, PUT, and DELETE glossary endpoints to tamper with instance-wide business glossary data without…
AplazadaAlta (7.1)0.44%—Chatbot UIAISupabaseAI4/9/202624/9/2026
Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file…
AplazadaCrítica (9.3)0.39%—Joodatabase LiteAI3/9/20263/9/2026
Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
Pendiente de análisisAlta (8.6)0.29%—BaserowAI2/9/20262/9/2026
Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. The vulnerable…
AplazadaMedia (5.1)0.30%—NocobaseAI2/9/202616/9/2026
NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the affected record.
AplazadaAlta (8.2)0.41%—Tooljet DatabaseAI31/8/202610/9/2026
ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables from any workspace by supplying victim…
AplazadaAlta (8.7)0.24%—Hulumi BaselineAI31/8/202631/8/2026
@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.
AplazadaAlta (7.1)0.30%—Budibase ServerAI28/8/202628/8/2026
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted…
AplazadaAlta (7.2)0.40%—BudibaseAI28/8/202628/8/2026
Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable premium features and downgrade deployments…
AplazadaCrítica (9.4)0.89%—BudibaseAI28/8/202628/8/2026
Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process, enabling attackers…
AplazadaAlta (8.3)0.33%—Budibase ServerAI28/8/202631/8/2026
Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers,…
AplazadaAlta (8.3)0.34%—BudibaseAI28/8/202628/8/2026
Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject…
Orbitaley — Vulnerabilidades