Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

5032 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.51%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
AnalizadaAlta (7.1)0.20%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
AnalizadaMedia (6.5)0.38%—IBM Datastage ON Cloud PAK FOR Data10/9/202616/9/2026
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
AplazadaAlta (8.8)2.9%💥 ExploitNewfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+19/9/20269/9/2026
Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —…
AplazadaMedia (6.9)0.61%—Ragic Enterprise Cloud DatabaseAI9/9/20269/9/2026
The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.
Pendiente de análisisMedia (6.6)0.31%—Tanium Data ServiceAI9/9/20269/9/2026
Tanium addressed a path traversal vulnerability in Tanium Data Service.
AnalizadaAlta (7.5)1.2%—Microsoft Asp.net Core Odata8/9/20265/10/2026
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
AplazadaAlta (8.5)0.18%—Unidata Netcdf-cAI4/9/202624/9/2026
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the destination buffer, causing memory corruption…
Pendiente de análisisMedia (5.3)0.23%—IBM Cloud PAK FOR Data SystemAI4/9/20268/9/2026
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
AplazadaCrítica (9.3)0.39%—Joodatabase LiteAI3/9/20263/9/2026
Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.
En análisisMedia (6.5)0.41%—Dell Powerprotect Data ManagerAI3/9/20265/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.
En análisisMedia (4.1)0.36%—Dell Powerprotect Data ManagerAI3/9/20263/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
En análisisAlta (7.8)0.20%—Dell Powerprotect Data ManagerAI3/9/20264/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
En análisisMedia (6.8)0.38%—Dell Powerprotect Data ManagerAI3/9/20264/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks.
AnalizadaMedia (5.3)0.33%—Data Field Project Data Field2/9/20269/9/2026
Missing Authorization vulnerability in Drupal Data field allows Forceful Browsing. This issue affects Data field versions: from 0.0.0 to 2.0.13.
Pendiente de análisisMedia (5.6)0.72%—Fasterxml Jackson-databindAI1/9/20268/9/2026
DefaultBaseTypeLimitingValidator is the PolymorphicTypeValidator applied automatically whenever @JsonTypeInfo is used without an explicitly configured custom validator. It denies polymorphic resolution only for a fixed set of "unsafe base types", and its isSafeSubType method returns true unconditionally for every base…
Pendiente de análisisMedia (5.3)0.53%—Fasterxml Jackson-databindAI1/9/20268/9/2026
jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.deserialize, a string bound from untrusted JSON is passed to new URI(value) and then to Path.of(uri). When that throws FileSystemNotFoundException, the…
AplazadaCrítica (9.3)0.40%—Wpdataaccess WP Data AccessAI31/8/20261/9/2026
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
AplazadaMedia (5.5)0.48%—Nasa Earthdata-searchAI31/8/20261/9/2026
A flaw has been found in NASA earthdata-search 1.0.0. Affected by this issue is the function OpenSearchGranuleSearchLambda of the file serverless/src/openSearchGranuleSearch/handler.js of the component granules Endpoint. Executing a manipulation of the argument openSearchOsdd can lead to server-side request forgery.…
AplazadaMedia (5.5)0.47%—Nasa Earthdata-searchAI31/8/20261/9/2026
A vulnerability was detected in NASA earthdata-search 1.0.0. Affected by this vulnerability is the function scaleImage of the file serverless/src/scaleImage/handler.js of the component scale Endpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit is…
AplazadaMedia (5.3)0.36%—DataeaseAI31/8/20268/9/2026
DataEase before 2.10.26 contains multiple access control defects in the sharing link module. Tickets are not bound to the target share UUID, so a valid ticket issued for one share can be reused against another (ShareTicketManage.validateTicket / POST /de2api/share/proxyInfo). The POST /de2api/share/validate endpoint…
AplazadaMedia (5.3)0.34%—DataeaseAI31/8/20268/9/2026
DataEase versions before 2.10.26 omit object-level authorization checks on geographic information, dashboard linkage, and chart detail REST endpoints, allowing authenticated users to access resources belonging to other users. Attackers can overwrite or delete map geometry, modify dashboard linkages, and retrieve chart…
AplazadaAlta (8.2)0.41%—Tooljet DatabaseAI31/8/202610/9/2026
ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables from any workspace by supplying victim…
Pendiente de análisisMedia (6.2)0.16%—IBM Cloud PAK FOR Data SystemAI28/8/202631/8/2026
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 is vulnerable to a denial of service due to improper limitation of resources.
AplazadaAlta (7.5)0.79%—Datadog DD Trace RSAI28/8/20269/9/2026
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair…