Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

1243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.32%—KA2 Custom-database-tablesAI9/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ka2 Custom DataBase Tables custom-database-tables allows Reflected XSS.This issue affects Custom DataBase Tables: from n/a through <= 2.1.34.
AplazadaAlta (7.5)0.51%—Wpseeds WP Database BackupAI9/1/202517/6/2026
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for unauthenticated attackers to extract sensitive data including all…
AplazadaMedia (6)0.25%—Teradata DatabaseAISuse Linux Enterprise ServerAI8/1/202517/6/2026
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts,…
AplazadaAlta (7.6)0.47%—Penguinarts Contact Form 7 Database Cfdb7AI7/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in penguinarts Contact Form 7 Database – CFDB7 advanced-cf7-database allows SQL Injection.This issue affects Contact Form 7 Database – CFDB7: from n/a through <= 1.0.0.
ModificadaAlta (8.6)0.59%—Amazon WEB Services Redshift Java Database Connectivity Driver24/12/202417/6/2026
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
AplazadaMedia (4.9)0.85%—Database Backup AND Check Tables Automated With SchedulerAI24/12/202417/6/2026
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the database_backup_ajax_download() function. This makes it possible for authenticated attackers, with administrator-level access and above, to…
AplazadaCrítica (9.8)0.56%—Nette DatabaseAI10/12/202417/6/2026
Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's position is that this is intended behavior.
AplazadaMedia (6.5)0.63%—Code4life Database FOR CF7AI9/12/202417/6/2026
Missing Authorization vulnerability in code4life Database for CF7 database-for-cf7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database for CF7: from n/a through <= 1.2.4.
AnalizadaAlta (8.8)0.45%—Cmorillas1 External Database Based Actions15/11/202417/6/2026
The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a missing capability check in the 'edba_admin_handle' function. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to…
AnalizadaAlta (7.2)1.2%—Microsoft Azure Database FOR Postgresql Flexible Server12/11/202417/6/2026
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
AnalizadaAlta (7.2)1.2%—Microsoft Azure Database FOR Postgresql Flexible Server12/11/202417/6/2026
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
ModificadaMedia (4.8)0.28%—Heimkino-praxis Movie Database18/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bert Movie Database movie-database allows Stored XSS.This issue affects Movie Database: from n/a through <= 1.0.11.
ModificadaBaja (3.1)0.39%—Oracle Database Server15/10/202417/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.…
AnalizadaBaja (3.5)0.46%—Oracle XML Database15/10/202417/6/2026
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via HTTP to compromise XML Database. Successful…
ModificadaMedia (4.3)0.42%—Oracle Database Server15/10/202417/6/2026
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database…
AnalizadaCrítica (9.8)0.65%—Ragic Enterprise Cloud Database15/10/202417/6/2026
Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it to execute arbitrary code on the remote server.
AnalizadaCrítica (9.8)0.57%—Ragic Enterprise Cloud Database15/10/202417/6/2026
Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session cookie.
AnalizadaAlta (7.5)0.67%—Ragic Enterprise Cloud Database15/10/202417/6/2026
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
AnalizadaCrítica (9.8)1.2%—Vesoft Nebulagraph Database22/9/202417/6/2026
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
AnalizadaCrítica (9.8)0.58%—Vesoft Nebulagraph Database22/9/202417/6/2026
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.
AplazadaCrítica (9.8)0.65%—Xnau Participants DatabaseAI13/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.
ModificadaAlta (7.2)0.53%—Oracle Database Server16/7/202417/6/2026
Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having Execute on SYS.XS_DIAG privilege with network access via Oracle Net to compromise Oracle Database RDBMS…
AnalizadaBaja (3.1)0.32%—Oracle Database Server16/7/202417/6/2026
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM.…
AnalizadaMedia (5.8)0.49%—Oracle Database Server16/7/202417/6/2026
Vulnerability in the Oracle Database Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.23 and 21.3-21.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via DNS to compromise Oracle Database Portable Clusterware. While the…
AnalizadaBaja (2.3)0.17%—Oracle Database Server16/7/202417/6/2026
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database…
Orbitaley — Vulnerabilidades