Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3071▲ 536 respecto a la semana anterior
Críticas / altas1456▲ 257 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)384▲ 177 respecto a la semana anterior
5025 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Alta (7.1) | — | — | 4TU Researchdata DjehutyAI | 1/10/2026 | 1/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject SPARQL into the search/listing queries through three separate parameters. Because the affected queries are read (SELECT) queries, this does not write to the store, but it allows:… | |
| Recibida | Alta (7.5) | — | — | Fasterxml Jackson-dataformats-binaryAI | 1/10/2026 | 1/10/2026 | The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained… | |
| Recibida | Alta (7.5) | — | — | Fasterxml Jackson Dataformats BinaryAI | 1/10/2026 | 1/10/2026 | The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and… | |
| Recibida | Alta (8.4) | — | — | 4tu.researchdata DjehutyAI | 1/10/2026 | 1/10/2026 | djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store.… | |
| Aplazada | Baja (2.1) | — | — | Datadrivenconstruction OpenconstructionerpAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session. The… | |
| Aplazada | Baja (2.1) | — | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (1.2) | — | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an… | |
| Pendiente de análisis | Baja (1.1) | — | — | Wikimedia CommonsmetadataAI | 30/9/2026 | 1/10/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in The Wikimedia Foundation MediaWiki CommonsMetadata extension allows Cross-Site Scripting (XSS). This issue affects MediaWiki CommonsMetadata extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Alta (7.5) | 0.45% | — | Kiteworks Secure Data FormsAI | 30/9/2026 | 1/10/2026 | Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, remote attacker to make the server issue arbitrary outbound network requests and read back the responses. This could potentially be used to reach internal-only services or other… | |
| Aplazada | Alta (8.8) | 0.52% | — | ALL IN ONE Structured DataAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions. | |
| Aplazada | Alta (8.2) | 0.35% | — | Wpdataaccess WP Data AccessAI | 30/9/2026 | 30/9/2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.84 versions. | |
| Aplazada | Baja (3.5) | 0.14% | — | ALL IN ONE Schemas Schema AND Structured Data FOR WP AND AMPAI | 30/9/2026 | 30/9/2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.67 does not perform a capability check when saving several of its fields, nor escape them when outputting them back, allowing users with the editor role and above to inject arbitrary web scripts that execute when a higher privileged user views the… | |
| En análisis | Crítica (9.1) | 0.68% | — | IBM Guardium Data ProtectionAI | 29/9/2026 | 30/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the certificate export CLI functionality, allowing a privileged authenticated CLI user to execute arbitrary commands with root privileges. | |
| En análisis | Alta (7.2) | 0.68% | — | IBM Guardium Data ProtectionAI | 29/9/2026 | 30/9/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the CLI certificate SMIME recipient deletion functionality, allowing an authenticated privileged CLI user to execute arbitrary commands with root privileges. | |
| En análisis | Alta (8.8) | 0.55% | — | IBM DatastageAI | 29/9/2026 | 29/9/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | Google MCP Toolbox FOR DatabasesAI | 29/9/2026 | 29/9/2026 | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks… | |
| Analizada | Alta (8.1) | 0.38% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity. | |
| Analizada | Alta (8.8) | 0.67% | — | IBM Guardium Data Protection | 29/9/2026 | 1/10/2026 | IBM Guardium Data Protection 12.2 is vulnerable to command injection in the SNMP alert notification functionality. An authenticated attacker who can influence policy alert text can cause attacker-controlled data to be executed as operating system commands by the SNMP alerter service, which runs with root privileges. | |
| Pendiente de análisis | Alta (7.5) | 0.15% | — | Wikimedia DatatransferAI | 29/9/2026 | 1/10/2026 | Dependency on Vulnerable Third-Party Component and Uncontrolled Resource Consumption vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Excessive Allocation. This issue affects Mediawiki - DataTransfer Extension: from 1.46.0 before 1.47.0. | |
| Pendiente de análisis | Media (6.3) | 0.39% | — | Apache Airflow Teradata ProviderAI | 29/9/2026 | 29/9/2026 | The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the… | |
| Pendiente de análisis | Media (6.5) | 0.28% | — | Apache Airflow Providers TeradataAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private… | |
| Aplazada | Crítica (9.9) | 0.36% | — | 3DS Geovia Geospatial Data ManagerAI | 29/9/2026 | 30/9/2026 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server. | |
| Aplazada | Alta (8.4) | 0.29% | — | Getgrav Grav Plugin DatamanagerAI | 26/9/2026 | 30/9/2026 | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by… | |
| Pendiente de análisis | Crítica (10) | 0.95% | — | Wikimedia External DataAI | 25/9/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData Extension: from * before 3.7. |