Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.55% | — | Stedb Corp Stedb FormsAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in STEdb Corp. STEdb Forms stedb-forms allows SQL Injection.This issue affects STEdb Forms: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7) | 0.27% | — | Enterprisedb Epas-uiAI | 12/3/2025 | 17/6/2026 | CWE-287: Improper Authentication vulnerability exists that could cause an Authentication Bypass when an unauthorized user without permission rights has physical access to the EPAS-UI computer and is able to reboot the workstation and interrupt the normal boot process. | |
| Aplazada | Media (6.5) | 0.30% | — | Jp2112 Feedburner Optin FormAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jp2112 Feedburner Optin Form feedburner-optin-form allows Stored XSS.This issue affects Feedburner Optin Form: from n/a through <= 0.2.8. | |
| Aplazada | Media (6.1) | 0.24% | — | Wikimedia Mediawiki Articlefeedbackv5AI | 10/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - ArticleFeedbackv5 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - ArticleFeedbackv5 extension: from 1.42.X before 1.42.2. | |
| Aplazada | Media (5.3) | 0.50% | — | Syedbalkhi User FeedbackAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi User Feedback userfeedback-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Feedback: from n/a through <= 1.0.10. | |
| Aplazada | Media (5) | 0.32% | — | Yugabytedb AnywhereAI | 13/11/2024 | 17/6/2026 | An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. This flaw results in the unintentional exposure of sensitive information in Yugabyte Anywhere logs, potentially allowing unauthorized users with access to these logs to view… | |
| Aplazada | Media (5.7) | 0.14% | — | YugabytedbanywhereAI | 13/11/2024 | 17/6/2026 | An information disclosure vulnerability exists in the backup configuration process where the SAS token is not masked in the configuration response. This oversight results in sensitive information leakage within the yb_backup log files, exposing the SAS token in plaintext. The leakage occurs during the backup… | |
| Analizada | Baja (2.4) | 0.32% | — | Authzed Spicedb | 14/10/2024 | 17/6/2026 | SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that have enabled `LookupResources2` and have caveats in the evaluation path for their requests can return a permissionship of `CONDITIONAL` with context… | |
| Analizada | Media (5.3) | 0.29% | — | Authzed Spicedb | 18/9/2024 | 17/6/2026 | spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on the same relation can result in no permission being returned when permission is expected. If the resource has multiple groups,… | |
| Analizada | Alta (7.5) | 0.51% | — | Yugabytedb | 3/9/2024 | 17/6/2026 | YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter. | |
| Modificada | Media (6.1) | 0.40% | — | Monsterinsights Userfeedback | 12/7/2024 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (5.4) | 0.34% | — | Syedbalkhi WP Lightbox 2 | 3/7/2024 | 17/6/2026 | The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 3.0.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (5.3) | 0.40% | — | Authzed Spicedb | 20/6/2024 | 17/6/2026 | Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is expected. If the resource exists under *multiple* folders and the… | |
| Modificada | Media (4.3) | 0.28% | — | Brainstormforce Surefeedback | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34. | |
| Analizada | Media (5.3) | 0.70% | — | Cratedb | 13/6/2024 | 17/6/2026 | CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated renegotiation. In this scenario, an attacker can exploit this feature to repeatedly request renegotiation of security parameters during an ongoing… | |
| Aplazada | Alta (7.7) | 0.53% | — | Enterprisedb Postgres Advanced ServerAI | 14/5/2024 | 17/6/2026 | All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 may allow users using edbldr to bypass role permissions from pg_read_server_files. This could allow low privilege users to read files to which they would not otherwise have access. | |
| Analizada | Media (4.3) | 0.58% | — | Authzed Spicedb | 10/4/2024 | 17/6/2026 | SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form: `relation folder: folder | folder#parent` with an arrow such as `folder->view` can cause LookupSubjects to only return the subjects found under subjects for either `folder` or `folder#parent`. This… | |
| Analizada | Crítica (9.1) | 0.46% | — | Authzed Spicedb | 1/3/2024 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements or panic. Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for… | |
| Modificada | Media (6.1) | 0.43% | — | Monsterinsights Userfeedback | 22/2/2024 | 17/6/2026 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_submitted' 'link' value in all versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (4.9) | 0.61% | — | Kurrent Eventstoredb | 21/2/2024 | 17/6/2026 | EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, 21 prior to 21.10.11, 22 prior to 22.10.5, and 23 prior to 23.10.1. Only database instances that use custom projections are affected by this… | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Cratedb | 30/1/2024 | 17/6/2026 | CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM function in the CrateDB database that is used to import file data into database tables. This function has a flaw, and authenticated attackers can use the COPY FROM function to… | |
| Modificada | Crítica (9.8) | 0.73% | — | Cratedb | 30/1/2024 | 17/6/2026 | CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the… | |
| Modificada | Media (6.1) | 0.44% | — | Qkmc-rk Redbbs | 11/1/2024 | 17/6/2026 | A vulnerability classified as problematic was found in qkmc-rk redbbs 1.0. Affected by this vulnerability is an unknown functionality of the component Nickname Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Media (5.4) | 0.43% | — | Qkmc-rk Redbbs | 11/1/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in qkmc-rk redbbs 1.0. Affected is an unknown function of the component Post Handler. The manipulation of the argument title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (7.2) | 0.62% | — | Svnlabs Html5 MP3 Player With Folder Feedburner Playlist Free | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0. |