Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2768 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.26% | — | BasercmsAI | 3/8/2026 | 28/8/2026 | BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed. | |
| Aplazada | Alta (8.2) | 0.42% | — | BudibaseAI | 1/8/2026 | 31/8/2026 | Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses,… | |
| Aplazada | Media (5.3) | 0.42% | — | Database Collation FIXAI | 1/8/2026 | 12/8/2026 | The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algorithm' parameter in all versions up to, and including, 1.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Xnau Participants DatabaseAI | 1/8/2026 | 26/8/2026 | The Participants Database WordPress plugin before 2.7.8.4 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Pendiente de análisis | Crítica (9.1) | 0.43% | — | SupabaseAI | 31/7/2026 | 8/9/2026 | Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration. | |
| Analizada | Alta (8) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the ValidateMCPAuth pipeline for opaque tokens skips… | |
| Analizada | Alta (8) | 0.13% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client (internal/sources/http/http.go) fails to… | |
| Analizada | Media (6.6) | 0.24% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into system memory using an unrestricted… | |
| Analizada | Media (5.7) | 0.20% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery dry-run API to enforce dataset… | |
| Analizada | Alta (8.1) | 0.25% | — | Google MCP Toolbox FOR Databases | 31/7/2026 | 8/8/2026 | Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints when the --enable-api flag is active. | |
| Aplazada | Media (6.1) | 0.27% | — | WP Real IP Based Access ControlAI | 30/7/2026 | 30/7/2026 | The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any… | |
| Pendiente de análisis | Alta (7.2) | 1.1% | — | Heimdall Data Database ProxyAI | 29/7/2026 | 30/7/2026 | Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Aplazada | Alta (7.2) | 0.43% | — | Database FOR CF7AI | 29/7/2026 | 30/7/2026 | The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in all versions up to, and including, 1.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.1) | 0.25% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 28/7/2026 | 28/7/2026 | The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before reflecting it back in an admin page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (6) | 0.19% | — | Google MCP Toolbox FOR Databases | 27/7/2026 | 28/9/2026 | A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox. The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport… | |
| Analizada | Media (6.5) | 0.49% | — | Apache Hbase | 24/7/2026 | 6/8/2026 | Missing Authorization vulnerability in Apache HBase thrift and rest delegation service. A scan operation in thrift/rest service has 3 steps, open, fetch(possible multiple times), close. The open step will return an id which will be passed back to server for identifying the scanner instances stored at server side. We… | |
| Aplazada | Media (5.3) | 0.42% | — | Xnau Participants DatabaseAI | 24/7/2026 | 24/7/2026 | The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the 'id' parameter. This makes it possible for unauthenticated attackers to overwrite arbitrary participant records by numeric ID and redirect the private_id-bearing… | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Aplazada | Crítica (10) | 0.60% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Wp-base BookingAI | 23/7/2026 | 23/7/2026 | Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Xnau Participants DatabaseAI | 23/7/2026 | 23/7/2026 | Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions. | |
| Pendiente de análisis | Media (5.3) | 0.40% | — | 389 Project 389 DS BaseAI | 22/7/2026 | 22/7/2026 | A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a denial of service or an arbitrary memory write operation. | |
| Analizada | Alta (8.3) | 0.39% | — | Oracle Installed Base | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Installed Base | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… |