Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.44% | — | Tablesome Table & Contact Form 7 DatabaseAI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.33. | |
| Aplazada | Alta (7.6) | 0.52% | — | ABW Badger-databaseAI | 17/6/2024 | 17/6/2026 | A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm. | |
| Modificada | Media (4.9) | 0.56% | — | Meowapps Database Cleaner | 10/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Cleaner allows Relative Path Traversal.This issue affects Database Cleaner: from n/a through 1.0.5. | |
| Aplazada | Alta (7.2) | 0.64% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 2/5/2024 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Media (4.3) | 0.20% | — | Peprodev CF7 DatabaseAI | 18/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pepro Dev. Group PeproDev CF7 Database.This issue affects PeproDev CF7 Database: from n/a through 1.8.0. | |
| Analizada | Media (4.2) | 0.25% | — | Oracle Database Server | 16/4/2024 | 17/6/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having Authenticated User privilege with logon to the infrastructure where RDBMS executes to compromise RDBMS. Successful… | |
| Modificada | Media (4.9) | 0.41% | — | Oracle Database Server | 16/4/2024 | 17/6/2026 | Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this… | |
| Modificada | Baja (2.4) | 0.53% | — | Oracle Database Server | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle Database Sharding.… | |
| Aplazada | Media (4.3) | 0.20% | — | Tablesome Table AND Contact Form 7 DatabaseAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.25. | |
| Aplazada | Alta (7.1) | 0.33% | — | Ninjateam Database FOR Contact Form 7AI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NinjaTeam Database for Contact Form 7 allows Stored XSS.This issue affects Database for Contact Form 7: from n/a through 3.0.6. | |
| Aplazada | Alta (7.1) | 0.42% | — | Pauple Table AND Contact Form 7 Database TablesomeAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pauple Table & Contact Form 7 Database – Tablesome allows Reflected XSS.This issue affects Table & Contact Form 7 Database – Tablesome: from n/a through 1.0.27. | |
| Aplazada | Media (6.4) | 0.59% | — | Database FOR Contact Form 7 Wpforms Elementor FormsAI | 13/3/2024 | 17/6/2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Alta (8.1) | 0.55% | — | Tencent Blueking Configuration Management Database | 26/2/2024 | 9/7/2026 | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request. | |
| Modificada | Media (4.7) | 0.27% | — | Webfactoryltd WP Database Reset | 21/2/2024 | 17/6/2026 | The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing or incorrect nonce validation on the install_wpr() function. This makes it possible for unauthenticated attackers to install the WP Reset Plugin via a forged request… | |
| Modificada | Baja (2.6) | 0.30% | — | Oracle Audit Vault AND Database Firewall | 17/2/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require… | |
| Analizada | Alta (7.5) | 0.43% | — | Oracle Audit Vault AND Database Firewall | 17/2/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this… | |
| Analizada | Media (6.5) | 0.42% | — | Oracle Database Server | 17/2/2024 | 17/6/2026 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.21 and 21.3-21.12. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful… | |
| Modificada | Alta (7.2) | 1.1% | — | Sigmaplugin Advanced Database Cleaner | 5/2/2024 | 17/6/2026 | The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.3 via deserialization of untrusted input in the 'process_bulk_action' function. This makes it possible for authenticated attacker, with administrator access and above, to inject a PHP… | |
| Modificada | Alta (7.2) | 1.2% | — | Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms | 31/1/2024 | 17/6/2026 | The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up to, and including, 1.3.2. This makes it possible for authenticated attackers with administrator-level capabilities or above, to upload arbitrary files on… | |
| Modificada | Alta (7.6) | 0.43% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require… | |
| Modificada | Baja (2.7) | 0.34% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this… | |
| Modificada | Baja (3) | 0.33% | — | Oracle Audit Vault AND Database Firewall | 16/1/2024 | 17/6/2026 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. While the vulnerability is… | |
| Modificada | Crítica (9.8) | 1.0% | — | Dmparekh Wordpress Database Administrator | 16/1/2024 | 17/6/2026 | The WordPress Database Administrator WordPress plugin through 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Modificada | Alta (7.8) | 0.43% | — | Crmperks Database FOR Contact Form 7, Wpforms, Elementor Forms | 16/1/2024 | 17/6/2026 | The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection. | |
| Modificada | Alta (7.5) | 0.48% | — | Meowapps Database Cleaner | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimize & Repair: from n/a through 0.9.8. |