Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
571 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.16% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 18/8/2026 | 21/8/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector.… | |
| Analizada | Alta (8.4) | 0.21% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when… | |
| Analizada | Alta (8.8) | 0.50% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination,… | |
| Analizada | Alta (8.8) | 0.40% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to… | |
| Analizada | Crítica (9.5) | 0.54% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and,… | |
| Analizada | Alta (7.1) | 0.32% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user… | |
| Aplazada | Media (6.5) | 0.33% | — | It-recht-kanzlei Legal Text ConnectorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Legal Text Connector of the IT-Recht Kanzlei <= 1.0.13 versions. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Qualys Container Scanning ConnectorAI | 5/8/2026 | 31/8/2026 | Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Aplazada | Media (4.9) | 0.44% | — | Gsheetconnector CF7 Google Sheets ConnectorAI | 1/8/2026 | 12/8/2026 | The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 5.2.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Mountdev AI MCP ConnectorAI | 23/7/2026 | 23/7/2026 | The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to obtain an… | |
| Analizada | Media (6.5) | 0.19% | — | Oracle Mysql Connector/j | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human… | |
| Analizada | Media (6.5) | 0.36% | — | Oracle Mysql Connector/j | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Mysql Connector/j | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Analizada | Alta (7.7) | 0.35% | — | Oracle Mysql Connector/j | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL… | |
| Analizada | Alta (8.6) | 0.41% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (7.7) | 0.33% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8) | 0.29% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applications). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Identity Manager Connector | 21/7/2026 | 28/7/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector.… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Mysql Connector/net | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Analizada | Alta (8.5) | 0.33% | — | Oracle Mysql Connector/net | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Mysql Connector/net | 21/7/2026 | 3/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are affected are 9.7.0-9.7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Analizada | Alta (7.5) | 0.47% | — | Oracle Mysql Connector/c++ | 21/7/2026 | 6/8/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++). Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… |