Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
2762 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9) | — | — | 389project 389 DS BaseAI | 1/10/2026 | 1/10/2026 | A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's… | |
| Recibida | Alta (7.5) | — | — | Port389 389-ds-baseAI | 1/10/2026 | 1/10/2026 | A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker… | |
| Aplazada | Alta (8.3) | — | — | BudibaseAI | 1/10/2026 | 1/10/2026 | Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an… | |
| Aplazada | Baja (2.1) | — | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (1.2) | — | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.… | |
| Pendiente de análisis | Baja (0.3) | 0.14% | — | Wikimedia WikbaseAI | 30/9/2026 | 30/9/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Alta (7.2) | 0.35% | — | Wikimedia WikibaseAI | 30/9/2026 | 30/9/2026 | Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Media (6.3) | 0.64% | — | VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+1 | 30/9/2026 | 30/9/2026 | A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the… | |
| Pendiente de análisis | Alta (8.6) | 0.34% | — | BasercmsAI | 30/9/2026 | 30/9/2026 | When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user. | |
| Aplazada | Media (5.1) | 0.14% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Media (5.1) | 0.15% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Media (6.9) | 0.33% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information. | |
| Aplazada | Media (5.1) | 0.14% | — | BasercmsAI | 30/9/2026 | 1/10/2026 | A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser. | |
| Aplazada | Crítica (9.1) | 0.24% | — | Bytebase DbhubAI | 29/9/2026 | 30/9/2026 | bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement. | |
| Aplazada | Alta (8.8) | 0.15% | — | Basecamp UprightAI | 29/9/2026 | 30/9/2026 | basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback. | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | Google MCP Toolbox FOR DatabasesAI | 29/9/2026 | 29/9/2026 | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks… | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia WikibaseAI | 29/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Aplazada | Alta (7.1) | 0.26% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source code. Attackers can supply a victim tenant's app id to retrieve sensitive… | |
| Aplazada | Alta (7) | 0.26% | — | Budibase ServerAI | 26/9/2026 | 28/9/2026 | Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete… | |
| Aplazada | Alta (8.6) | 0.21% | — | BudibaseAI | 26/9/2026 | 30/9/2026 | Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in… | |
| Aplazada | Alta (8.3) | 0.21% | — | BudibaseAI | 26/9/2026 | 30/9/2026 | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and… | |
| Aplazada | Crítica (9.2) | 0.33% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and… | |
| Aplazada | Alta (8.9) | 0.21% | — | BudibaseAI | 26/9/2026 | 28/9/2026 | Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier /… | |
| Aplazada | Alta (8.7) | 0.57% | — | Budibase ServerAI | 26/9/2026 | 30/9/2026 | Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary… | |
| Aplazada | Media (6.3) | 0.25% | — | BudibaseAI | 26/9/2026 | 30/9/2026 | Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. Attackers can submit a crafted POST request to inject an attacker-controlled… |