Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2768 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.30%—Budibase Backend-coreAIBudibaseAI28/8/202628/8/2026
Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default blacklist is active (i.e., a self-hosted deployment has not defined BLACKLIST_IPS),…
AplazadaAlta (8.6)0.36%—BudibaseAI28/8/202628/8/2026
Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with builder.apps fields to escalate…
AplazadaAlta (8.6)0.39%—BudibaseAI28/8/202628/8/2026
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table…
AplazadaMedia (5.1)0.44%—Watchguard Dimension Database ServerAI28/8/202628/8/2026
A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
AplazadaMedia (6.1)0.25%—Bilpark Informatics Technologies Industry AND Trade DoxbaseAI27/8/202628/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in BilPark Informatics Technologies Industry and Trade Inc. DoXBASE allows Cross Zone Scripting. This issue affects DoXBASE: through 27082026. NOTE: The vendor was contacted early about this disclosure but did not…
AplazadaAlta (8.7)0.57%—BaserowAI27/8/202623/9/2026
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that admits any caller, so a request carrying no credential reaches the…
Pendiente de análisisMedia (6.5)0.78%—389 Project 389 DS BaseAI25/8/20268/9/2026
A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource exhaustion and a Denial of Service (DoS) for…
AplazadaMedia (5.3)0.33%—BaserowAI24/8/202623/9/2026
Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-frontend/modules/core/editor/mention.js builds its element with a template literal that places the name into a data-label…
AplazadaMedia (6.2)0.44%—Hepta Platforms INC HeptabaseAI24/8/202626/8/2026
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
AplazadaAlta (8.1)0.47%—Firebase AuthenticationAI22/8/202626/8/2026
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.
AnalizadaCrítica (10)0.80%—Microsoft Azure SQL Database21/8/20264/9/2026
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.9)0.99%—Microsoft Azure SQL Database20/8/202624/8/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.9)0.99%—Microsoft Azure SQL Database20/8/202624/8/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
AnalizadaCrítica (9.1)0.86%—Microsoft Azure SQL Database20/8/202624/8/2026
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (7.2)1.3%—Heimdall Data Database ProxyAI20/8/20261/9/2026
Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
AplazadaAlta (8.6)0.50%—BasercmsAI20/8/202631/8/2026
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a…
AplazadaMedia (6.5)0.22%—Wp-base WP Base BookingAI20/8/202620/8/2026
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
AnalizadaCrítica (9.1)0.45%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Portable Clusterware. Successful attacks of this…
AnalizadaMedia (5.3)0.32%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can…
ModificadaCrítica (9.6)0.40%—Oracle Database Server18/8/202622/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaCrítica (9.6)0.40%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…
AnalizadaAlta (8.5)0.33%—Oracle Database Server18/8/202620/8/2026
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,…
AnalizadaMedia (6.3)0.26%—Oracle Installed Base18/8/20263/9/2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of…
AnalizadaCrítica (9.8)0.51%—Oracle Essbase18/8/20263/9/2026
Vulnerability in Oracle Essbase (component: Infrastructure). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle…
AnalizadaAlta (8.8)0.43%—Oracle Essbase18/8/20263/9/2026
Vulnerability in Oracle Essbase (component: Calculator). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase.…
Orbitaley — Vulnerabilidades