Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
232 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.43% | — | Enterprisedb Postgres Advanced Server | 23/4/2023 | 17/6/2026 | EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and… | |
| Modificada | Alta (7.5) | 0.76% | — | Authzed Spicedb | 14/4/2023 | 17/6/2026 | SpiceDB is an open source, Google Zanzibar-inspired, database system for creating and managing security-critical application permissions. The `spicedb serve` command contains a flag named `--grpc-preshared-key` which is used to protect the gRPC API from being accessed by unauthorized requests. The values of this flag… | |
| Modificada | Media (5.5) | 0.19% | — | Edb-debugger Project Edb-debugger | 4/4/2023 | 17/6/2026 | An issue found in Eteran edb-debugger v.1.3.0 allows a local attacker to causea denial of service via the collect_symbols function in plugins/BinaryInfo/symbols.cpp. | |
| Modificada | Media (4.3) | 0.51% | — | THM Feedbacksystem | 7/3/2023 | 17/6/2026 | thmmniii/fbs-core is an open source feedback system for students. In versions prior to 1.5.3 when querying `subresults`, it is possible to query `subresults` from other users due to insufficient authorisation. This is only possible for logged-in users and it is not possible to associate the subresults with a specific… | |
| Modificada | Crítica (9.8) | 0.70% | — | Litedb | 24/2/2023 | 17/6/2026 | LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserialization of Untrusted Data. LiteDB uses a special field in JSON documents to cast different types from `BsonDocument` to POCO classes. When instances of an object are not the same of class, `BsonMapper`… | |
| Modificada | Alta (8.8) | 0.78% | — | Timescaledb | 14/2/2023 | 17/6/2026 | TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data collection were not run with a locked down… | |
| Modificada | Crítica (9.8) | 0.51% | — | Yugabytedb Managed | 9/2/2023 | 17/6/2026 | The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary files through the backup upload endpoint by using path traversal characters. This vulnerability is associated with program files PlatformReplicationManager.Java. This issue affects YugabyteDB Anywhere: from 2.0.0.0 through… | |
| Modificada | Crítica (9.8) | 0.78% | — | Yugabytedb | 9/2/2023 | 17/6/2026 | External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated… | |
| Modificada | Crítica (9.8) | 0.64% | — | Yugabytedb Managed | 9/2/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF), Improperly Controlled Modification of Dynamically-Determined Object Attributes, Improper Restriction of Excessive Authentication Attempts vulnerability in YugaByte, Inc. Yugabyte Managed allows Accessing Functionality Not Properly Constrained by ACLs, Communication Channel… | |
| Modificada | Crítica (9.8) | 0.66% | — | Lolfeedback Project Lolfeedback | 15/1/2023 | 17/6/2026 | A vulnerability has been found in lolfeedback and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection. The identifier of the patch is 6cf0b5f2228cd8765f734badd37910051000f2b2. It is recommended to apply a patch to fix this issue. The identifier… | |
| Modificada | Media (5.4) | 0.55% | — | Jenkins Extreme-feedback | 21/9/2022 | 17/6/2026 | A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps. | |
| Modificada | Crítica (9.8) | 0.91% | — | Yugabytedb | 12/8/2022 | 17/6/2026 | An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Extreme Feedback Panel | 30/6/2022 | 17/6/2026 | Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.42% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+12 | 2/6/2022 | 17/6/2026 | Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product… | |
| Modificada | Alta (8) | 0.90% | — | Timescaledb | 13/3/2022 | 17/6/2026 | Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer (which executes as Superuser), leading to… | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… | |
| Modificada | Alta (8.8) | 0.68% | — | Schneider-electric Hmibscea53d1edb FirmwareSchneider-electric Hmibscea53d1eds FirmwareSchneider-electric Hmibscea53d1edm FirmwareSchneider-electric Hmibscea53d1edl Firmware+3 | 9/2/2022 | 17/6/2026 | A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink… | |
| Modificada | Alta (7.4) | 0.94% | — | Schneider-electric Hmibscea53d1edb FirmwareSchneider-electric Hmibscea53d1eds FirmwareSchneider-electric Hmibscea53d1edm FirmwareSchneider-electric Hmibscea53d1edl Firmware+3 | 9/2/2022 | 17/6/2026 | A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink… | |
| Modificada | Alta (8.1) | 1.3% | — | Authzed Spicedb | 11/1/2022 | 17/6/2026 | SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard relationship under the right hand branch of an `exclusion` or within an `intersection` operation will see `Lookup`/`LookupResources` return a resource as "accessible" if it is *not* accessible by… | |
| Modificada | Crítica (9.8) | 1.2% | — | Flumedb Project Flumedb | 27/12/2021 | 17/6/2026 | An issue was discovered in the flumedb crate through 2021-01-07 for Rust. read_entry may read from uninitialized memory locations. | |
| Modificada | Crítica (9.8) | 1.2% | — | Bronzedb-protocol Project Bronzedb-protocol | 27/12/2021 | 17/6/2026 | An issue was discovered in the bronzedb-protocol crate through 2021-01-03 for Rust. ReadKVExt may read from uninitialized memory locations. | |
| Modificada | Media (6.1) | 0.64% | — | Nzedb Project Nzedb | 2/12/2021 | 17/6/2026 | nZEDb v0.4.20 is affected by a Cross Site Scripting (XSS) vulnerability in www/pages/api.php. The exit function will terminate the script and print the message which has the input $_GET['t']. | |
| Modificada | Media (5.3) | 0.87% | — | Nedb Project Nedb | 15/6/2021 | 17/6/2026 | This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload. | |
| Modificada | Media (6.1) | 0.85% | — | Ougc Feedback Project Ougc Feedback | 9/3/2021 | 17/6/2026 | The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation. | |
| Modificada | Media (6.5) | 1.5% | — | Libesedb Project Libesedb | 1/9/2018 | 17/6/2026 | The libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based buffer over-read via a crafted esedb file. NOTE: the vendor has disputed this as described in the GitHub issue comments |