Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.32% | — | KA2 Custom-database-tablesAI | 9/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBase Tables custom-database-tables allows Reflected XSS.This issue affects Custom DataBase Tables: from n/a through <= 2.1.34. | |
| Aplazada | Alta (7.5) | 0.51% | — | Wpseeds WP Database BackupAI | 9/1/2025 | 17/6/2026 | The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all… | |
| Aplazada | Media (6) | 0.25% | — | Teradata DatabaseAISuse Linux Enterprise ServerAI | 8/1/2025 | 17/6/2026 | Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts,… | |
| Aplazada | Alta (7.6) | 0.47% | — | Penguinarts Contact Form 7 Database Cfdb7AI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contact Form 7 Database – CFDB7 advanced-cf7-database allows SQL Injection.This issue affects Contact Form 7 Database – CFDB7: from n/a through <= 1.0.0. | |
| Modificada | Alta (8.6) | 0.59% | — | Amazon WEB Services Redshift Java Database Connectivity Driver | 24/12/2024 | 17/6/2026 | A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30. | |
| Aplazada | Media (4.9) | 0.85% | — | Database Backup AND Check Tables Automated With SchedulerAI | 24/12/2024 | 17/6/2026 | The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Nette DatabaseAI | 10/12/2024 | 17/6/2026 | Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior. | |
| Aplazada | Media (6.5) | 0.63% | — | Code4life Database FOR CF7AI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in code4life Database for CF7 database-for-cf7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database for CF7: from n/a through <= 1.2.4. | |
| Analizada | Alta (8.8) | 0.45% | — | Cmorillas1 External Database Based Actions | 15/11/2024 | 17/6/2026 | The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to… | |
| Analizada | Alta (7.2) | 1.2% | — | Microsoft Azure Database FOR Postgresql Flexible Server | 12/11/2024 | 17/6/2026 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.2) | 1.2% | — | Microsoft Azure Database FOR Postgresql Flexible Server | 12/11/2024 | 17/6/2026 | Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability | |
| Modificada | Media (4.8) | 0.28% | — | Heimkino-praxis Movie Database | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bert Movie Database movie-database allows Stored XSS.This issue affects Movie Database: from n/a through <= 1.0.11. | |
| Modificada | Baja (3.1) | 0.39% | — | Oracle Database Server | 15/10/2024 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.… | |
| Analizada | Baja (3.5) | 0.46% | — | Oracle XML Database | 15/10/2024 | 17/6/2026 | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful… | |
| Modificada | Media (4.3) | 0.42% | — | Oracle Database Server | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database… | |
| Analizada | Crítica (9.8) | 0.65% | — | Ragic Enterprise Cloud Database | 15/10/2024 | 17/6/2026 | Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server. | |
| Analizada | Crítica (9.8) | 0.57% | — | Ragic Enterprise Cloud Database | 15/10/2024 | 17/6/2026 | Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie. | |
| Analizada | Alta (7.5) | 0.67% | — | Ragic Enterprise Cloud Database | 15/10/2024 | 17/6/2026 | Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. | |
| Analizada | Crítica (9.8) | 1.2% | — | Vesoft Nebulagraph Database | 22/9/2024 | 17/6/2026 | An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection. | |
| Analizada | Crítica (9.8) | 0.58% | — | Vesoft Nebulagraph Database | 22/9/2024 | 17/6/2026 | An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Xnau Participants DatabaseAI | 13/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2. | |
| Modificada | Alta (7.2) | 0.53% | — | Oracle Database Server | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS… | |
| Analizada | Baja (3.1) | 0.32% | — | Oracle Database Server | 16/7/2024 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.… | |
| Analizada | Media (5.8) | 0.49% | — | Oracle Database Server | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 and 21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. While the… | |
| Analizada | Baja (2.3) | 0.17% | — | Oracle Database Server | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database… |