Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

232 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.43%—Enterprisedb Postgres Advanced Server23/4/202317/6/2026
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and…
ModificadaAlta (7.5)0.76%—Authzed Spicedb14/4/202317/6/2026
SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by unauthorized requests. The values of this flag…
ModificadaMedia (5.5)0.19%—Edb-debugger Project Edb-debugger4/4/202317/6/2026
An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp.
ModificadaMedia (4.3)0.51%—THM Feedbacksystem7/3/202317/6/2026
thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to associate the subresults with a specific…
ModificadaCrítica (9.8)0.70%—Litedb24/2/202317/6/2026
LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserialization of Untrusted Data. LiteDB uses a special field in JSON documents to cast different types from `BsonDocument` to POCO classes. When instances of an object are not the same of class, `BsonMapper`…
ModificadaAlta (8.8)0.78%—Timescaledb14/2/202317/6/2026
TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data collection were not run with a locked down…
ModificadaCrítica (9.8)0.51%—Yugabytedb Managed9/2/202317/6/2026
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through…
ModificadaCrítica (9.8)0.78%—Yugabytedb9/2/202317/6/2026
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated…
ModificadaCrítica (9.8)0.64%—Yugabytedb Managed9/2/202317/6/2026
Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel…
ModificadaCrítica (9.8)0.66%—Lolfeedback Project Lolfeedback15/1/202317/6/2026
A vulnerability has been found in lolfeedback and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The identifier of the patch is 6cf0b5f2228cd8765f734badd37910051000f2b2. It is recommended to apply a patch to fix this issue. The identifier…
ModificadaMedia (5.4)0.55%—Jenkins Extreme-feedback21/9/202217/6/2026
A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.
ModificadaCrítica (9.8)0.91%—Yugabytedb12/8/202217/6/2026
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.
ModificadaMedia (5.4)0.64%—Jenkins Extreme Feedback Panel30/6/202217/6/2026
Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaAlta (8.8)0.42%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+122/6/202217/6/2026
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product…
ModificadaAlta (8)0.90%—Timescaledb13/3/202217/6/2026
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer (which executes as Superuser), leading to…
ModificadaMedia (5.5)0.23%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+2011/2/202217/6/2026
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health…
ModificadaAlta (8.8)0.68%—Schneider-electric Hmibscea53d1edb FirmwareSchneider-electric Hmibscea53d1eds FirmwareSchneider-electric Hmibscea53d1edm FirmwareSchneider-electric Hmibscea53d1edl Firmware+39/2/202217/6/2026
A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink…
ModificadaAlta (7.4)0.94%—Schneider-electric Hmibscea53d1edb FirmwareSchneider-electric Hmibscea53d1eds FirmwareSchneider-electric Hmibscea53d1edm FirmwareSchneider-electric Hmibscea53d1edl Firmware+39/2/202217/6/2026
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink…
ModificadaAlta (8.1)1.3%—Authzed Spicedb11/1/202217/6/2026
SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as "accessible" if it is *not* accessible by…
ModificadaCrítica (9.8)1.2%—Flumedb Project Flumedb27/12/202117/6/2026
An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations.
ModificadaCrítica (9.8)1.2%—Bronzedb-protocol Project Bronzedb-protocol27/12/202117/6/2026
An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations.
ModificadaMedia (6.1)0.64%—Nzedb Project Nzedb2/12/202117/6/2026
nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t'].
ModificadaMedia (5.3)0.87%—Nedb Project Nedb15/6/202117/6/2026
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
ModificadaMedia (6.1)0.85%—Ougc Feedback Project Ougc Feedback9/3/202117/6/2026
The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.
ModificadaMedia (6.5)1.5%—Libesedb Project Libesedb1/9/201817/6/2026
The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments
Orbitaley — Vulnerabilidades