Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.27% | — | Elastic Kibana | 1/9/2026 | 4/9/2026 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Improper Handling of Highly Compressed Data (CWE-409) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding Streams management privileges could supply specially crafted content that expands to a far larger volume of data during processing, exhausting the memory… | |
| Analizada | Media (6.5) | 0.46% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Improper Neutralization of Special Elements in Data Query Logic (CWE-943) in Kibana can lead to information disclosure via NoSQL Injection (CAPEC-676). An authenticated user with access to the affected query functionality could submit specially crafted input that alters the intended query logic, returning data the… | |
| Analizada | Alta (8.3) | 0.50% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to privilege escalation via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). A user holding workflow edit permissions could cause scheduled workflow executions to run with the privileges of a different, higher-privileged user, allowing… | |
| Analizada | Media (6.5) | 0.42% | — | Elastic Kibana | 1/9/2026 | 2/9/2026 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level permissions could submit a specially crafted request that causes excessive resource consumption, which may render Kibana unavailable. | |
| Aplazada | Media (5.3) | 0.34% | — | DolibarrAI | 30/8/2026 | 10/9/2026 | Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity… | |
| Aplazada | Alta (8.7) | 0.35% | — | Alibaba Qwen-agentAIGradioAI | 28/8/2026 | 23/9/2026 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal… | |
| Aplazada | Alta (7.1) | 0.30% | — | Budibase ServerAI | 28/8/2026 | 28/8/2026 | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud metadata endpoints and other restricted… | |
| Aplazada | Alta (7.2) | 0.40% | — | BudibaseAI | 28/8/2026 | 28/8/2026 | Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable premium features and downgrade deployments… | |
| Aplazada | Crítica (9.4) | 0.89% | — | BudibaseAI | 28/8/2026 | 28/8/2026 | Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process, enabling attackers… | |
| Aplazada | Alta (8.3) | 0.33% | — | Budibase ServerAI | 28/8/2026 | 31/8/2026 | Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making requests to attacker-controlled servers,… | |
| Aplazada | Alta (8.3) | 0.34% | — | BudibaseAI | 28/8/2026 | 28/8/2026 | Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the destination workspace. Attackers can inject… | |
| Aplazada | Alta (7.1) | 0.30% | — | Budibase Backend-coreAIBudibaseAI | 28/8/2026 | 28/8/2026 | Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default blacklist is active (i.e., a self-hosted deployment has not defined BLACKLIST_IPS),… | |
| Aplazada | Alta (8.6) | 0.36% | — | BudibaseAI | 28/8/2026 | 28/8/2026 | Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate… | |
| Aplazada | Alta (8.6) | 0.39% | — | BudibaseAI | 28/8/2026 | 28/8/2026 | Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table… | |
| Analizada | Alta (8.8) | 0.56% | — | Dolibarr Erp/crm | 27/8/2026 | 31/8/2026 | Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to… | |
| Analizada | Alta (7.1) | 0.39% | — | Dolibarr Erp/crm | 27/8/2026 | 31/8/2026 | Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE /api/index.php/documents, while the sibling builddoc() path passes… | |
| Analizada | Alta (8.6) | 0.44% | — | Dolibarr Erp/crm | 27/8/2026 | 31/8/2026 | Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and… | |
| Analizada | Media (4.2) | 0.20% | — | Elastic Kibana | 25/8/2026 | 2/9/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, an authenticated user could reference another user's AI Assistant conversation identifier to access or modify… | |
| Analizada | Media (5.3) | 0.36% | — | Dolibarr Erp/crm | 24/8/2026 | 31/8/2026 | Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project creation permission but without access to a… | |
| Aplazada | Alta (7.1) | 0.41% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list endpoints to obtain crypted password… | |
| Aplazada | Alta (7.1) | 0.38% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can perform binary search on numeric fields and… | |
| Aplazada | Alta (7.1) | 0.42% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity fields. Attackers can manipulate workflow… | |
| Aplazada | Alta (7.1) | 0.39% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite salary, bonus, hourly rate, daily rate,… | |
| Aplazada | Alta (7.1) | 0.39% | — | DolibarrAI | 24/8/2026 | 8/9/2026 | Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company.… |