Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 15/7/2026 | 15/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when… | |
| Aplazada | Alta (8.7) | 0.56% | — | CapgoAISupabase PostgrestAI | 12/7/2026 | 13/7/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the /rest/v1/global_stats endpoint to expose MRR,… | |
| Aplazada | Alta (7.1) | 0.43% | — | CapgoAIPostgrestAI | 10/7/2026 | 10/7/2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can modify sensitive channel attributes such… | |
| Aplazada | Media (6.9) | 0.36% | — | CapgoAISupabase PostgrestAI | 8/7/2026 | 8/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by the anon role using only the public sb_publishable_* key. An unauthenticated attacker can probe organization existence and leak sensitive… | |
| Aplazada | Alta (8.7) | 0.43% | — | CapgoAISupabase PostgrestAI | 8/7/2026 | 8/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing unauthenticated access. Because the function accepts a caller-supplied user UUID without verifying it matches the authenticated user, an… | |
| Aplazada | Baja (3.3) | 0.31% | — | Docker ComposeAIRedisAIKeydbAIDragonflyAI+4 | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the… | |
| Aplazada | Alta (8.8) | 0.89% | — | PostgresqlAICoollabs CoolifyAI | 7/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handling did not sufficiently restrict paths, allowing an authenticated… | |
| Aplazada | Alta (8.8) | 0.65% | — | PostgresqlAICoollabs CoolifyAI | 6/7/2026 | 7/7/2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell-form commands, allowing an authenticated user to inject commands… | |
| Analizada | Alta (8.2) | 0.24% | — | Postgresql Jdbc Driver | 6/7/2026 | 9/7/2026 | pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who… | |
| Analizada | Media (4.3) | 0.19% | — | Dalibo Postgresql Anonymizer | 30/6/2026 | 6/7/2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions | |
| Aplazada | Crítica (9.3) | 0.53% | — | Raytha CMSAIPostgresqlAI | 30/6/2026 | 30/6/2026 | Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL statements against the underlying PostgreSQL database, leading to full database compromise, including credential extraction. Because vendor contact… | |
| Aplazada | Media (6) | 0.38% | — | NocodbAIPostgresqlAI | 23/6/2026 | 25/6/2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd permission on a Postgres-backed base can inject arbitrary SQL into the formula engine via the optional direction argument of ARRAYSORT(...). The value is unrestricted by formula validation and embedded… | |
| Aplazada | Alta (8.7) | 0.49% | — | Capgo BackendAISupabase PostgrestAIPostgresqlAI | 23/6/2026 | 23/6/2026 | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries… | |
| Aplazada | Alta (8.6) | 0.39% | — | CapgoAIPostgrestAI | 23/6/2026 | 23/6/2026 | Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS… | |
| Aplazada | Media (6.9) | 0.40% | — | CapgoAIPostgresqlAI | 20/6/2026 | 23/6/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that exposes internal PostgreSQL replication telemetry including slot names and WAL LSN positions. Attackers can access this endpoint without authentication to retrieve sensitive infrastructure details… | |
| Aplazada | Media (6.9) | 0.39% | — | Supabase PostgrestAICapgoAI | 20/6/2026 | 24/6/2026 | Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauthenticated attacker using only the public Supabase API key… | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 20/6/2026 | 22/6/2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows unauthenticated attackers to enumerate organizations and disclose billing status using the public sb_publishable key. Attackers can invoke these endpoints to determine… | |
| Aplazada | Alta (8.7) | 0.37% | — | CapgoAISupabaseAIPostgrestAI | 19/6/2026 | 22/6/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert… | |
| Aplazada | Alta (7.1) | 0.41% | — | CapgoAIPostgrestAI | 19/6/2026 | 22/6/2026 | Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs. Attackers can query the webhooks and webhook_deliveries endpoints to exfiltrate HMAC signing secrets and delivery… | |
| Aplazada | Media (4.7) | 0.08% | — | Steeltoe Configuration AbstractionsAIMysqlAIPostgresqlAI | 17/6/2026 | 22/6/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those… | |
| Analizada | Alta (7.5) | 0.25% | — | Dalibo Postgresql Anonymizer | 11/6/2026 | 17/6/2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuser calls the import_database_rules() or import_roles_rules() functions, the malicious code is executed with superuser… | |
| Aplazada | Alta (8.6) | 0.53% | — | Mem0AIPostgresqlAI | 9/6/2026 | 23/7/2026 | Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure endpoint modifies global LLM provider and embedder configuration but only verifies authentication via JWT or X-API-Key without validating the caller's role.… | |
| Aplazada | Baja (1.1) | 0.08% | — | Yoanbernabeu GrepaiAIPostgresqlAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in yoanbernabeu grepai up to 0.35.0. The affected element is the function PostgresStore.LookupByContentHash of the file indexer/chunker.go of the component Postgres Embedding Cache. Executing a manipulation of the argument content_hash can lead to use of weak hash. The attack needs to be… | |
| Pendiente de análisis | Alta (8.6) | 0.30% | — | Amazon Aurora PostgresqlAIAmazon Advanced GO WrapperAI | 5/6/2026 | 17/6/2026 | An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when… |