Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
1016 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.41% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, packages/server/src/api/controllers/automation.ts returned automation test results containing trigger.outputs.user.oauth2, broadcast BuilderSocketEvent.AutomationTestProgress to the app room, and stored progress in… | |
| Aplazada | Media (4.9) | 0.43% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.4, uploadUrl in packages/server/src/utilities/fileUtils.ts used a bare server-side fetch for string attachment values passed by processAttachments in packages/server/src/sdk/workspace/ai/helpers/rows.ts. A builder with the AI table-generation feature could… | |
| Aplazada | Media (5.3) | 0.44% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, POST /api/global/auth/:tenantId/login incremented the failure counter in packages/worker/src/api/controllers/global/auth.ts only for existing users, while packages/worker/src/middleware/emailLockout.ts returned X-Account-Locked and Retry-After only for… | |
| Aplazada | Alta (8.2) | 0.31% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim account identifier can start the… | |
| Aplazada | Media (4.3) | 0.34% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.39.25, the GET /api/global/groups endpoint in packages/worker/src/api/routes/global/groups.ts omitted auth.builderOrAdmin, allowing an authenticated BASIC role user to enumerate tenant groups, role mappings and user memberships, builder permissions, and… | |
| Aplazada | Crítica (9.6) | 0.56% | — | BudibaseAI | 12/8/2026 | 8/9/2026 | Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database… | |
| Aplazada | Media (5.3) | 0.37% | — | Dolibarr ERPAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Pendiente de análisis | Media (6.9) | 0.43% | 💥 PoC | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user… | |
| Pendiente de análisis | Baja (2.4) | 0.22% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users. | |
| Pendiente de análisis | Media (6.9) | 0.40% | — | Sharp MFPAIToshibatec MFPAI | 3/8/2026 | 3/8/2026 | Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product. | |
| Aplazada | Alta (8.2) | 0.42% | — | BudibaseAI | 1/8/2026 | 31/8/2026 | Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects against the IP blacklist. Attackers with Builder role can configure a REST datasource pointing to an external server that returns a redirect to internal IP addresses,… | |
| Aplazada | Media (5.8) | 0.40% | — | Alibabacloud RDS Openapi MCP ServerAI | 28/7/2026 | 28/7/2026 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listening on all network interfaces by default. | |
| Aplazada | Crítica (9) | 0.66% | 💥 PoC | Alibaba FastjsonAI | 23/7/2026 | 23/7/2026 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required. | |
| Analizada | Media (4.3) | 0.28% | — | Elastic Kibana | 22/7/2026 | 3/8/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control. | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory and become unavailable to all users. | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request payload. Processing this user-supplied… | |
| Analizada | Media (4.3) | 0.29% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access. | |
| Analizada | Media (4.3) | 0.27% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a Machine Learning management endpoint performs… | |
| Analizada | Media (4.3) | 0.33% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the documented API. The accessible data may… | |
| Analizada | Media (5) | 0.29% | — | Elastic Kibana | 21/7/2026 | 3/8/2026 | Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that should be denied by the configured… | |
| Analizada | Media (5.4) | 0.23% | — | Elastic Kibana | 21/7/2026 | 6/8/2026 | Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints. | |
| Pendiente de análisis | Baja (2.9) | 0.08% | — | LibarchiveAI | 21/7/2026 | 21/9/2026 | A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting… | |
| Analizada | Media (6.5) | 0.47% | — | Elastic Kibana | 21/7/2026 | 6/8/2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated low-privileged user can exploit an uncontrolled resource consumption vulnerability in Kibana's Canvas functionality by sending a specially crafted request, causing the Kibana… | |
| Analizada | Alta (7.1) | 0.35% | — | Elastic Kibana | 21/7/2026 | 6/8/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and case attachment integrity compromise via Privilege Abuse (CAPEC-122). An inconsistency in Kibana's file access authorization logic allows a low-privileged authenticated user to retrieve, modify, and… |