Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 0.45% | — | Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI | 26/8/2026 | 31/8/2026 | An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project… | |
| Aplazada | Media (6.4) | 0.21% | — | Cdata Fd614gs3-r850AI | 19/2/2026 | 17/6/2026 | Buffer Overflow vulnerability in CDATA FD614GS3-R850 V3.2.7_P161006 (Build.0333.250211) allows an attacker to execute arbitrary code via the node_mac, node_opt, opt_param, and domainblk parameters of the mesh_node_config and domiainblk_config modules | |
| Analizada | Media (4.3) | 0.39% | — | Cdata API Server | 2/9/2025 | 17/6/2026 | CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of CData API Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the usage of MySQL… | |
| Aplazada | Media (6.5) | 0.31% | — | Logicdata Ecommerce FrameworkAI | 19/8/2025 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Aplazada | Media (5.3) | 0.50% | — | Logicdata Ecommerce FrameworkAI | 19/8/2025 | 17/6/2026 | An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack. | |
| Aplazada | Alta (8.6) | 2.9% | — | Cdata SyncAIEclipse JettyAI | 5/4/2024 | 17/6/2026 | A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions. | |
| Aplazada | Alta (8.6) | 3.0% | — | Cdata ARCAIEclipse JettyAI | 5/4/2024 | 17/6/2026 | A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions. | |
| Aplazada | Crítica (9.8) | 6.1% | — | Cdata ConnectAIJettyAI | 5/4/2024 | 17/6/2026 | A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application. | |
| Aplazada | Crítica (9.8) | 8.1% | — | Cdata API ServerAIEclipse JettyAI | 5/4/2024 | 17/6/2026 | A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application. | |
| Modificada | Alta (7.5) | 0.76% | — | Cdatatec WEB Management System | 18/6/2023 | 17/6/2026 | A vulnerability was found in C-DATA Web Management System up to 20230607. It has been classified as critical. This affects an unknown part of the file /cgi-bin/jumpto.php?class=user&page=config_save&isphp=1 of the component User Creation Handler. The manipulation of the argument user/newpassword leads to improper… | |
| Modificada | Alta (7.5) | 4.0% | — | Cdata ARC | 16/6/2023 | 17/6/2026 | CData RSB Connect v22.0.8336 was discovered to contain a Server-Side Request Forgery (SSRF). | |
| Modificada | Crítica (9.8) | 44% | — | Cdatatec C-data WEB Management System | 1/12/2022 | 17/6/2026 | A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument hostname leads to argument injection. The attack may be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 35% | — | Cdatatec Fd702xw-x-r430 Firmware | 24/5/2022 | 17/6/2026 | C-DATA FD702XW-X-R430 v2.1.13_X001 was discovered to contain a command injection vulnerability via the va_cmd parameter in formlanipv6. This vulnerability allows attackers to execute arbitrary commands via a crafted HTTP request. | |
| Modificada | Alta (7.5) | 0.54% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. A custom encryption… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. There is a default… | |
| Modificada | Crítica (9.8) | 1.5% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. Attackers can discover… | |
| Modificada | Alta (7.5) | 1.9% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. It allows remote… | |
| Modificada | Crítica (9.8) | 2.0% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+25 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. One can escape from a… | |
| Modificada | Media (5.9) | 0.67% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. By default, the… | |
| Modificada | Crítica (9.8) | 1.4% | — | Cdatatec 72408a FirmwareCdatatec 9008a FirmwareCdatatec 9016a FirmwareCdatatec 92408a Firmware+24 | 24/11/2020 | 17/6/2026 | An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S-R2, FD1216S-R1, FD1608GS, FD1608SN, FD1616GS, FD1616SN, and FD8000 devices. Attackers can use… | |
| Modificada | Crítica (9.8) | 1.8% | — | Cdatatec Epon Cpe-wifi Devices Firmware | 3/1/2019 | 17/6/2026 | EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies. | |
| Modificada | Baja (2.1) | 0.35% | — | Mcdata Intrepid 6064 Director SwitchMcdata Intrepid 6140 Director SwitchMcdata Sphereon 4300 Fabric SwitchMcdata Sphereon 4500 Fabric Switch | 7/8/2005 | 16/6/2026 | Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm. |