Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.35% | — | SAP Hana CockpitSAP Hana Database Explorer | 14/4/2026 | 17/6/2026 | Information Disclosure Vulnerability in SAP HANA Cockpit and HANA Database Explorer | |
| Aplazada | Media (4.3) | 0.28% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 1/4/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the entries_shortcode() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Contributor-level… | |
| Analizada | Media (5.5) | 0.57% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Media (5.5) | 0.70% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The manipulation of the argument manager_id leads to improper authorization. It is possible to initiate the attack remotely.… | |
| Analizada | Baja (2.1) | 0.46% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_user_delete.php of the component Endpoint. Executing a manipulation of the argument user_id can lead to improper authorization. The attack may be performed from remote. The… | |
| Analizada | Media (5.5) | 0.57% | — | Lerouxyxchire Client Database Management System | 8/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of the argument manager_id causes improper authorization. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.8) | 1.0% | — | Database FOR Contact Form 7AI | 5/3/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.7 via deserialization of untrusted input in the 'download_csv' function. This makes it possible for unauthenticated attackers to inject a PHP Object. No known… | |
| Analizada | Media (5.3) | 0.37% | — | MariadbAmazon Aurora MysqlAmazon Relational Database Service | 3/3/2026 | 14/7/2026 | In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Database Software Training Consulting LTD Databank Accreditation SoftwareAI | 19/2/2026 | 25/6/2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd. Databank Accreditation Software allows SQL Injection. This issue affects Databank Accreditation Software: before 2026/04. | |
| Aplazada | Media (5.3) | 0.45% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/1/2026 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the CSV export functionality in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to download sensitive form submission… | |
| Analizada | Alta (7) | 0.20% | — | Oracle Database Server | 20/1/2026 | 17/6/2026 | Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a… | |
| Analizada | Alta (8.7) | 0.53% | — | Gotac Statistics Database System | 16/1/2026 | 17/6/2026 | Statistics Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly exploit a specific functionality to query database contents. | |
| Analizada | Alta (8.7) | 0.66% | — | Gotac Statistics Database System | 16/1/2026 | 17/6/2026 | Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Analizada | Alta (8.8) | 0.33% | — | SAP Hana Database | 13/1/2026 | 17/6/2026 | SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system�s confidentiality, integrity, and availability. | |
| Aplazada | Media (6.4) | 0.28% | — | Sigmaplugin Advanced Database Cleaner PROAI | 7/1/2026 | 30/9/2026 | Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10. | |
| Analizada | Crítica (9.3) | 0.53% | — | Ragic Enterprise Cloud Database | 22/12/2025 | 17/6/2026 | Enterprise Cloud Database developed by Ragic has a Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information and log into the system as any user. | |
| Analizada | Alta (8.7) | 0.61% | — | Ragic Enterprise Cloud Database | 22/12/2025 | 17/6/2026 | Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Aplazada | Media (6.4) | 0.32% | — | Teclib Database Inventory PluginAI | 19/12/2025 | 17/6/2026 | pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. Prior to version 1.1.2, in certain conditions (database write access must first be obtained through another vulnerability or misconfiguration), user-controlled… | |
| Analizada | Baja (2.1) | 0.35% | — | Lerouxyxchire Client Database Management System | 18/12/2025 | 17/6/2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Crítica (9.9) | 0.32% | — | Redefiningtheweb Wordpress Contact Form 7 PDF Google Sheet & DatabaseAI | 18/12/2025 | 5/10/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contact Form 7 PDF, Google Sheet & Database: from n/a through <= 3.0.0. | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Media (4.3) | 0.29% | — | Teclib Database Inventory PluginAI | 18/11/2025 | 17/6/2026 | pluginsGLPI's Database Inventory Plugin "manages" the Teclib' inventory agents in order to perform an inventory of the databases present on the workstation. In versions prior to 1.0.3, any authenticated user could send requests to agents. This issue has been patched in version 1.0.3. | |
| Analizada | Baja (2.1) | 0.31% | — | 1000projects Design & Development OF Student Database Management System | 17/11/2025 | 30/9/2026 | A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The manipulation of the argument SubCode results in sql injection. The attack may be performed from remote. The exploit is… | |
| Analizada | Alta (7.1) | 0.20% | — | Lerouxyxchire Client Database Management System | 10/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST… |