Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.51% | — | Budibase ServerAI | 13/8/2026 | 31/8/2026 | Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are interpolated into JSON query templates without proper sanitization of JSON metacharacters. Attackers with query write permission can inject JSON structural characters to… | |
| Aplazada | Alta (7.1) | 0.34% | — | BudibaseAI | 13/8/2026 | 31/8/2026 | Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are enriched with handlebars using noEscaping: true and parsed without operator filtering. Attackers can inject MongoDB operators through query parameters to bypass per-user access… | |
| Aplazada | Media (6.6) | 0.51% | — | Baseline-browser-mappingAI | 13/8/2026 | 9/9/2026 | baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. | |
| Aplazada | Media (5.1) | 0.32% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKeyFile and tlsCAFile values directly to MongoClient on Budibase Cloud. A builder could submit absolute server paths through /api/datasources/verify and distinguish… | |
| Aplazada | Crítica (9) | 0.54% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the datasource origin. An unauthenticated caller of a PUBLIC POST… | |
| Aplazada | Alta (7.5) | 0.51% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user identifier, distinguish existing users… | |
| Aplazada | Media (5.7) | 0.41% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in… | |
| Aplazada | Media (4.9) | 0.43% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in packages/server/src/sdk/workspace/ai/helpers/rows.ts. A builder with the AI table-generation feature could… | |
| Aplazada | Media (5.3) | 0.44% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/emailLockout.ts returned X-Account-Locked and Retry-After only for… | |
| Aplazada | Alta (8.2) | 0.31% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim account identifier can start the… | |
| Aplazada | Media (4.3) | 0.34% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and… | |
| Aplazada | Crítica (9.6) | 0.56% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database… | |
| Pendiente de análisis | Media (5.9) | 0.51% | — | 389 Project 389 DS BaseAI | 12/8/2026 | 14/8/2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote… | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure SQL Database | 11/8/2026 | 17/8/2026 | Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally. | |
| Pendiente de análisis | Alta (7.1) | 0.40% | — | MetabaseAI | 10/8/2026 | 26/8/2026 | Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. | |
| Pendiente de análisis | Crítica (10) | 0.79% | — | MetabaseAI | 10/8/2026 | 26/8/2026 | Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) parameter. | |
| Analizada | Crítica (10) | 19% | ⚠ Explotación activa💥 Exploit | Metabase | 10/8/2026 | 12/8/2026 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. | |
| Aplazada | Baja (1.9) | 0.15% | — | Phialsbasement Koboldcpp-mcp-serverAI | 9/8/2026 | 12/8/2026 | A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It is possible to launch the attack on the… | |
| Aplazada | Baja (1.9) | 1.1% | — | Nighttrek Supabase-mcpAI | 9/8/2026 | 12/8/2026 | A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulation of the argument schema results in command injection. The attack needs to be… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | Datadog Android ApplicationAIGoogle Firebase CrashlyticsAI | 7/8/2026 | 3/9/2026 | In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying outside Datadog's own systems. | |
| Analizada | Crítica (10) | 0.90% | — | Microsoft Azure SQL Database | 7/8/2026 | 8/8/2026 | Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Baja (2.1) | 0.32% | — | BaserowAI | 4/8/2026 | 12/8/2026 | A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the component Inactive Non-Staff User Handler. Performing a manipulation results in improper authorization. Remote… | |
| Aplazada | Baja (2.3) | 0.43% | — | BaserowAI | 4/8/2026 | 12/8/2026 | A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify Endpoint. Such manipulation leads to improper authentication. The attack may be launched remotely. This attack is… | |
| Aplazada | Media (6.8) | 0.39% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 4/8/2026 | 26/8/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by users granted a specific capability which is limited to administrators by default but can be delegated… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Go-baseAI | 3/8/2026 | 10/9/2026 | go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary users, including admin roles, and completely… |