Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3081▲ 625 respecto a la semana anterior
Críticas / altas1483▲ 317 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

2762 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9)——389project 389 DS BaseAI1/10/20261/10/2026
A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered to the client in place of the client's…
RecibidaAlta (7.5)——Port389 389-ds-baseAI1/10/20261/10/2026
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker…
AplazadaAlta (8.3)——BudibaseAI1/10/20261/10/2026
Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl function in packages/server/src/utilities/fileUtils.ts uses raw node-fetch instead of fetchWithBlacklist. Authenticated builder users can send a prompt to POST /api/ai/tables that places an…
AplazadaBaja (2.1)——David-crty DatabasementAI1/10/20261/10/2026
A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has…
AplazadaBaja (1.2)——David-crty DatabasementAI1/10/20261/10/2026
A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.…
Pendiente de análisisBaja (0.3)0.14%—Wikimedia WikbaseAI30/9/202630/9/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki Wikbase extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki Wikbase extension: 1.46, 1.45, and 1.43.
Pendiente de análisisAlta (7.2)0.35%—Wikimedia WikibaseAI30/9/202630/9/2026
Deserialization of untrusted data vulnerability in The Wikimedia Foundation MediaWiki Wikibase extension allows Leverage Executable Code in Non-Executable Files. This issue affects MediaWiki Wikibase extension: 1.46, 1.45, and 1.43.
Pendiente de análisisMedia (6.3)0.64%—VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+130/9/202630/9/2026
A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the…
Pendiente de análisisAlta (8.6)0.34%—BasercmsAI30/9/202630/9/2026
When converting baserCMS4-style addons to baserCMS5-style ones, BcAddonMigrator includes "config.php" from the addon, which means the PHP code in the file is executed. Arbitrary files on the system may be read or deleted by an administrative user.
AplazadaMedia (5.1)0.14%—BasercmsAI30/9/20261/10/2026
A stored cross-site scripting vulnerability via custom content descriptions exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
AplazadaMedia (5.1)0.15%—BasercmsAI30/9/20261/10/2026
A cross-site scripting vulnerability via script validation bypass exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
AplazadaMedia (6.9)0.33%—BasercmsAI30/9/20261/10/2026
A missing authentication for critical function vulnerability exists in baserCMS. If this vulnerability is exploited, a remote attacker may obtain sensitive information.
AplazadaMedia (5.1)0.14%—BasercmsAI30/9/20261/10/2026
A stored cross-site scripting vulnerability via appended strings in email form fields exists in baserCMS. If this vulnerability is exploited, an arbitrary script may be executed in the user's web browser.
AplazadaCrítica (9.1)0.24%—Bytebase DbhubAI29/9/202630/9/2026
bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.
AplazadaAlta (8.8)0.15%—Basecamp UprightAI29/9/202630/9/2026
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.
Pendiente de análisisAlta (8.6)0.37%—Google MCP Toolbox FOR DatabasesAI29/9/202629/9/2026
Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks…
Pendiente de análisisMedia (6.1)0.15%—Wikimedia WikibaseAI29/9/202630/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Stored XSS. This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.
AplazadaAlta (7.1)0.26%—BudibaseAI26/9/202628/9/2026
Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/:appId/appPackage endpoint that allows authenticated users to read another tenant's application metadata and source code. Attackers can supply a victim tenant's app id to retrieve sensitive…
AplazadaAlta (7)0.26%—Budibase ServerAI26/9/202628/9/2026
Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table updates to the Builder collaboration websocket room. Attackers with Builder access can intercept unredacted datasource objects containing database passwords and API keys by observing table save or delete…
AplazadaAlta (8.6)0.21%—BudibaseAI26/9/202630/9/2026
Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endpoint, allowing builders to assign application roles across workspace boundaries. A builder of a single workspace can exploit missing per-app authorization checks to grant themselves admin roles in…
AplazadaAlta (8.3)0.21%—BudibaseAI26/9/202630/9/2026
Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enumerate chat identity link records across all workspaces in a tenant. Attackers with builder access to a single workspace can retrieve sensitive chat identity linking data including user IDs and…
AplazadaCrítica (9.2)0.33%—BudibaseAI26/9/202628/9/2026
Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. In sso.authenticate, when no existing user matches the incoming SSO subject, the server looks up pending user invites by the IdP-asserted email address alone — without validating an invite code and…
AplazadaAlta (8.9)0.21%—BudibaseAI26/9/202628/9/2026
Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlTable.ts by interpolating identifiers directly into a raw query string (backtick-quoted for MySQL, a single-quoted sp_rename literal for MSSQL) without applying the project's quoteMySqlIdentifier /…
AplazadaAlta (8.7)0.57%—Budibase ServerAI26/9/202630/9/2026
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary…
AplazadaMedia (6.3)0.25%—BudibaseAI26/9/202630/9/2026
Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability in the Microsoft Teams webhook endpoint that accepts forged Bot Framework activities with arbitrary serviceUrl values. Attackers can submit a crafted POST request to inject an attacker-controlled…