Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.39% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Alta (7.8) | 0.16% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base… | |
| Analizada | Media (5.6) | 0.13% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Enterprise Manager Install). Supported versions that are affected are 13.5 and 24.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise… | |
| Analizada | Alta (8.6) | 0.37% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Enterprise Manager Base Platform | 18/8/2026 | 26/8/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Application Config Console). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise… | |
| Aplazada | Alta (8.5) | 0.28% | — | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a Node agent, but the REST integration used getDispatcher from packages/backend-core/src/utils/fetch.ts, causing undici to ignore that agent and resolve the hostname again.… | |
| Aplazada | Alta (8.4) | 0.45% | — | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts interpolates the user-controlled schema configuration field into a SET search_path statement without escaping embedded double quotes, allowing an authenticated… | |
| Aplazada | Alta (7.1) | 0.35% | 💥 PoC | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts and packages/server/src/api/controllers/static/index.ts allows an authenticated published-app user with the BASIC role to supply attacker-controlled bucket and key values… | |
| Aplazada | Alta (7.1) | 0.46% | — | BudibaseAI | 17/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages/server/src/automations/steps/zapier.ts, packages/server/src/automations/steps/n8n.ts, packages/server/src/automations/steps/slack.ts, and… | |
| Aplazada | Alta (8.3) | 0.31% | — | BudibaseAI | 14/8/2026 | 31/8/2026 | Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 PutObject presigned URLs by sending POST requests to the attachments endpoint. The route was changed from a BUILDER permission check to a TABLE/WRITE check, which BASIC… | |
| Aplazada | Alta (7.6) | 0.45% | — | BudibaseAI | 13/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an unescaped tableName into a DESCRIBE statement. An attacker able to create a MySQL table with a backtick and stacked statement in its name could wait for a Budibase… | |
| Aplazada | Alta (8.8) | 0.52% | — | BudibaseAI | 13/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking appBuilder.appId or role.appId in packages/server/src/api/controllers/public/globalRoleValidation.ts. An app-scoped builder could scope the request to an app they control… | |
| Aplazada | Media (4.9) | 0.48% | — | BudibaseAI | 13/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id returned user objects processed by packages/server/src/utilities/global.ts without removing oauth2.accessToken or oauth2.refreshToken. A user with the POWER role could retrieve the identity-provider… | |
| Aplazada | Crítica (9) | 0.43% | — | BudibaseAI | 13/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-core/src/middleware/passport/sso/sso.ts then used users.getGlobalUserByEmail as a… | |
| Aplazada | Alta (8.3) | 0.35% | — | BudibaseAIGoogle FirebaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection strings and Firebase private keys in plaintext. Attackers with table read permissions can retrieve datasource configurations through the read API to obtain live backend… | |
| Aplazada | Alta (8.6) | 0.47% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) endpoint. On self-hosted instances (SELF_HOSTED or DISABLE_ACCOUNT_PORTAL set), the cloudRestricted middleware is a no-op and the route is protected only by a general… | |
| Aplazada | Alta (8.4) | 0.38% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated builder-level users to bypass DNS pinning protections through DNS rebinding attacks. Attackers can configure hostnames that resolve to public addresses during validation… | |
| Aplazada | Alta (8.8) | 0.34% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table names in identifiers. Attackers with write permission on a table with a double-quote in its name can inject SQL that executes as the datasource's database user to read or… | |
| Aplazada | Crítica (9) | 0.42% | — | BudibaseAISnowflakeAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data… | |
| Aplazada | Crítica (9.4) | 0.60% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any… | |
| Aplazada | Alta (8.7) | 0.16% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity… | |
| Aplazada | Media (5.4) | 0.18% | — | Basecamp UprightAIPrometheusAIPrometheus AlertmanagerAI | 13/8/2026 | 8/9/2026 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as… | |
| Aplazada | Crítica (10) | 0.69% | — | Wp-base BookingAI | 13/8/2026 | 14/8/2026 | Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. | |
| Aplazada | Alta (7.4) | 0.43% | — | Xnau Participants DatabaseAI | 13/8/2026 | 14/8/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. |