Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.87% | — | Mariadb Connector/jAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set is UTF-8. The server can report a… | |
| Pendiente de análisis | Media (5.9) | 0.39% | — | Mariadb Connector JAIMariadbAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind a secure… | |
| Pendiente de análisis | Media (5.9) | 0.44% | — | Mariadb Connector/jAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Connector/J can accept… | |
| Pendiente de análisis | Media (6.5) | 0.47% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client… | |
| Pendiente de análisis | Media (5.9) | 0.42% | — | Mariadb Connector/node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In… | |
| Analizada | Media (6) | 0.37% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying… | |
| Analizada | Alta (8.7) | 0.49% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Mariadb Connector Node.jsAI | 28/8/2026 | 8/9/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In… | |
| Analizada | Alta (8.7) | 0.42% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read from the client had no deadline, each… | |
| Analizada | Alta (8.7) | 0.25% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the sole means of identifying users, a… | |
| Analizada | Alta (8.7) | 0.46% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the resulting error is not handled and the shared… | |
| Analizada | Alta (8.3) | 0.42% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and, after the configured retries are… | |
| Analizada | Alta (8.5) | 0.42% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB collection can choose a name that closes… | |
| Analizada | Media (5.7) | 0.30% | — | Mongodb BI Connector | 28/8/2026 | 29/9/2026 | In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by SHOW CREATE statements without complete escaping of backslash characters. A user with permission to modify a collection's schema validator, in deployments configured to… | |
| Analizada | Media (4.1) | 0.10% | — | Mongodb BI Connector | 27/8/2026 | 23/9/2026 | In MongoDB Connector for BI, mongodrdl may write a TLS private-key password to standard error when the password is supplied through both the connection URI and the corresponding command-line option. A local user with access to the captured command output and encrypted key file may use the disclosed password to access… | |
| Analizada | Alta (8.2) | 0.28% | — | Mongodb BI Connector | 27/8/2026 | 23/9/2026 | An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling condition. This can interrupt BI Connector availability until the process restarts. | |
| Pendiente de análisis | Crítica (9.1) | 0.66% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | |
| Pendiente de análisis | Crítica (9.1) | 0.53% | — | Zscaler Client ConnectorAIZscaler Client Connector PortalAI | 24/8/2026 | 28/8/2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Attack Analyzer Connector FOR Splunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in… | |
| Analizada | Baja (3.3) | 0.16% | — | Oracle Agile PLM Mcad Connector | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise… | |
| Analizada | Media (4.8) | 0.25% | — | Oracle Agile PLM Mcad Connector | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks… | |
| Analizada | Media (5.3) | 0.34% | — | Oracle Agile PLM Mcad Connector | 18/8/2026 | 25/8/2026 | Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of… |