Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
5112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.22% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.60, contain(s) an Improper Certificate Validation vulnerability in certificate-based login. A low… | |
| Analizada | Alta (7.2) | 1.1% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a command injection vulnerability. A high privileged attacker with remote access could… | |
| Analizada | Media (5.7) | 0.33% | — | Dell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain appliances with Data Domain Operating System (DD OS) of Feature Release versions 8.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10 contain an insertion of sensitive information into log file vulnerability. A low privileged attacker with remote access could potentially… | |
| Analizada | Alta (8.4) | 0.16% | — | Dell Powerprotect DP Series ApplianceDell Data Domain Operating System | 17/4/2026 | 17/6/2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.13.1.0 through 7.13.1.50, contain a use of weak credentials vulnerability. An unauthenticated attacker with local access… | |
| Analizada | Alta (7.8) | 0.11% | — | Dell Data Domain Operating System | 17/4/2026 | 7/10/2026 | Dell PowerProtect Data Domain BoostFS para cliente de versiones Feature Release 7.7.1.0 hasta 8.5, versión LTS2025 8.3.1.0 hasta 8.3.1.20, versiones LTS2024 7.13.1.0 hasta 7.13.1.50, contienen una vulnerabilidad de credenciales insuficientemente protegidas. Un atacante con pocos privilegios y acceso local podría… | |
| Analizada | Alta (7.5) | 0.76% | 💥 PoC | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocity-1.7.jar, which pulls in commons-collections-3.2.1.jar containing the InvokerTransformer deserialization gadget chain. Quartz 2.3.2, also bundled in the application, deserializes job data BLOBs from… | |
| Analizada | Alta (8.7) | 0.52% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /de2api/datasetData/previewSql endpoint. The user-supplied SQL is wrapped in a subquery without validation that the input is a single SELECT statement. Combined with the JDBC… | |
| Analizada | Alta (8.3) | 0.43% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC parameter blocklist bypass vulnerability in the MySQL datasource configuration. The Mysql class uses Lombok's @Data annotation, which auto-generates a public setter for the illegalParameters field that… | |
| Analizada | Alta (8.6) | 0.52% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the /datasource/getTableField endpoint. The getTableFiledSql method in CalciteProvider.java incorporates the tableName parameter directly into SQL query strings using String.format… | |
| Analizada | Alta (8.6) | 0.50% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource update process. When a new table definition is added during a datasource update via /de2api/datasource/update, the deTableName field from the user-submitted… | |
| Analizada | Alta (8.7) | 0.49% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the API datasource saving process. The deTableName field from the Base64-encoded datasource configuration is used to construct a DDL statement via simple string replacement without… | |
| Analizada | Alta (8.7) | 0.49% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the sort parameter of the /de2api/datasetData/enumValueObj endpoint. The DatasetDataManage service layer directly transfers the user-supplied sort value to the sorting metadata DTO,… | |
| Analizada | Alta (8.7) | 0.49% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection vulnerability in the orderDirection parameter used in dataset-related endpoints including /de2api/datasetData/enumValueDs and /de2api/datasetTree/exportDataset. The Order2SQLObj class directly… | |
| Analizada | Alta (8.7) | 0.49% | — | Dataease | 16/4/2026 | 17/6/2026 | DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerability in the dataset export functionality. The expressionTree parameter in POST /de2api/datasetTree/exportDataset is deserialized into a filtering object and passed to WhereTree2Str.transFilterTrees… | |
| Analizada | Media (4.3) | 0.35% | — | SAP Hana CockpitSAP Hana Database Explorer | 14/4/2026 | 17/6/2026 | Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer | |
| Analizada | Media (5.5) | 0.13% | — | Dell Powerprotect Data Manager | 8/4/2026 | 24/7/2026 | Dell PowerProtect Agent Service, versión(es) anterior(es) a la 20.1, contiene una vulnerabilidad de asignación de permisos incorrecta para recursos críticos. Un atacante con pocos privilegios con acceso local podría potencialmente explotar esta vulnerabilidad, lo que lleva a la exposición de información. | |
| Aplazada | Media (5.3) | 0.29% | — | Rapid CAR Check Vehicle DataAI | 8/4/2026 | 24/7/2026 | Vulnerabilidad de autorización faltante en Rapid Car Check Rapid Car Check Vehicle Data free-vehicle-data-uk permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Rapid Car Check Vehicle Data: desde n/a hasta <= 2.0. | |
| Analizada | Alta (7.3) | 0.26% | — | Nvidia Data Loading Library | 7/4/2026 | 9/7/2026 | NVIDIA DALI contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to arbitrary code execution. | |
| Aplazada | Media (6.5) | 0.45% | 💥 PoC | Kedro-datasetsAI | 7/4/2026 | 17/6/2026 | Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vulnerable to path traversal. Partition IDs were concatenated directly with the dataset base path without validation. An attacker or malicious input containing .. components in a partition ID could… | |
| Analizada | Crítica (9.8) | 0.90% | — | Microsoft Azure Databricks | 3/4/2026 | 24/7/2026 | Falsificación de petición del lado del servidor (SSRF) en Azure Databricks permite a un atacante no autorizado elevar privilegios a través de una red. | |
| Aplazada | Baja (2) | 0.38% | — | Dataease SqlbotAI | 2/4/2026 | 24/7/2026 | Se determinó una vulnerabilidad en Dataease SQLbot hasta 1.6.0. Este problema afecta a la función get_es_data_by_http del archivo backend/apps/db/es_engine.py del componente Elasticsearch Gestor. Esta manipulación del argumento address causa falsificación de petición del lado del servidor. El ataque puede iniciarse… | |
| Aplazada | Media (5.5) | 0.41% | — | Alejandroarciniegas Mcp-data-visAI | 2/4/2026 | 17/6/2026 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation leads to sql injection. The attack may be… | |
| Analizada | Alta (8.8) | 0.17% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions… | |
| Analizada | Media (6.8) | 0.25% | — | IBM Datapower Gateway | 1/4/2026 | 17/6/2026 | IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0 through 10.5.0.20 and IBM DataPower Gateway 10.6.0 10.6.0.0 through 10.6.0.8 IBM DataPower Gateway could disclose sensitive system information from other domains to an administrative user. | |
| Aplazada | Baja (2.1) | 0.26% | — | Microsoft DataverseAI | 1/4/2026 | 17/6/2026 | A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attack is possible. The… |