Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 329 respecto a la semana anterior
Críticas / altas1353▲ 95 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

628 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.4)0.40%—KeycloakAIMysqlAIMariadbAI17/9/202622/9/2026
A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such…
Pendiente de análisisBaja (3.7)0.37%—Mariadb Connector JAI17/9/202623/9/2026
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL…
AplazadaMedia (6.5)0.22%—Product Variations Swatches FOR WoocommerceAI3/9/20264/9/2026
Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
Pendiente de análisisMedia (5.9)0.23%—Mariadb Connector R2dbcAI28/8/20268/9/2026
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a plugin to require a secure connection. A…
Pendiente de análisisMedia (5.9)0.49%—Mariadb Connector R2dbcAIMariadbAIMysqlAI28/8/20268/9/2026
MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to character_set_client through the…
Pendiente de análisisMedia (5.9)0.87%—Mariadb Connector/jAIMariadbAIOracle MysqlAI28/8/20268/9/2026
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set is UTF-8. The server can report a…
Pendiente de análisisMedia (5.9)0.39%—Mariadb Connector JAIMysqlAIMariadbAI28/8/20268/9/2026
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind a secure…
Pendiente de análisisMedia (5.9)0.44%—Mariadb Connector/jAI28/8/20268/9/2026
MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Connector/J can accept…
Pendiente de análisisMedia (6.5)0.47%—Mariadb Connector/node.jsAIMysqlAI28/8/20268/9/2026
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client…
Pendiente de análisisMedia (5.9)0.42%—Mariadb Connector/node.jsAI28/8/20268/9/2026
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In…
Pendiente de análisisAlta (7.5)0.57%—Mariadb Connector Node.jsAI28/8/20268/9/2026
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In…
AplazadaAlta (8.8)0.39%—MariadbAI27/8/202628/8/2026
The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of database error messages via PDOException. This…
AplazadaAlta (8.8)0.47%—MariadbAI27/8/202628/8/2026
A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate…
AplazadaCrítica (9.3)0.48%—MariadbAI27/8/202628/8/2026
The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results in detailed database error messages and…
AplazadaMedia (4)0.16%—Aria2AI25/8/20268/9/2026
aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.
AplazadaMedia (6.2)0.16%—Aria2AI24/8/20268/9/2026
Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service
AplazadaAlta (7.1)0.25%—Swatchly - Woocommerce Variation Swatches FOR ProductsAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions.
Pendiente de análisisAlta (7.1)0.45%—KohaAIMariadbAIMysqlAI11/8/202628/8/2026
A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL payload in the agefield value of an automatic item modification rule. The agefield value is stored…
AplazadaMedia (6.4)0.67%—DokployAIPostgresqlAIMariadbAIMysqlAI+210/8/20268/9/2026
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, usernames, and passwords into nested shell command strings passed to…
AplazadaCrítica (9.9)0.65%—DokployAIPostgresqlAIMariadbAIMysqlAI+110/8/20268/9/2026
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the value in nested shell…
Pendiente de análisisAlta (7.5)0.61%—MariadbAIMinioAIRedhat Data Science Pipelines OperatorAI10/8/202621/9/2026
A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a…
AplazadaBaja (2.1)0.43%—Akariasai Self RAGAI13/7/202613/7/2026
A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to…
Pendiente de análisisAlta (7.6)0.47%—Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI10/7/202613/7/2026
LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without…
Pendiente de análisisMedia (5.3)0.31%—Bitnami Mariadb GaleraAIBitnami Mariadb Galera Helm ChartAI18/6/202622/6/2026
Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted…
ModificadaAlta (7.2)1.6%—Mariadb12/6/20263/8/2026
MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute…