Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
1242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | — | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was determined in David-Crty databasement up to 1.7.1. Affected is the function SnapshotPolicy.viewAny/SnapshotPolicy.view of the file /api/v1/snapshots of the component Snapshot Model. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (1.2) | — | — | David-crty DatabasementAI | 1/10/2026 | 1/10/2026 | A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal.… | |
| Pendiente de análisis | Alta (8.6) | 0.37% | — | Google MCP Toolbox FOR DatabasesAI | 29/9/2026 | 29/9/2026 | Improper link resolution (CWE-59 / CWE-22) in the allowedLocalRoots path validation in Google MCP Toolbox for Databases versions 1.2.0 through 1.9.0 allows a remote authenticated attacker with tool execution permissions to bypass directory boundary restrictions via symbolic links. Because path validation checks… | |
| Aplazada | Crítica (9.1) | 0.51% | — | DatabasementAI | 22/9/2026 | 23/9/2026 | Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can load the page while pending, then accept the invitation after the legitimate user… | |
| Aplazada | Alta (8.1) | 0.37% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in takeover of RDBMS.… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Database ServerAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Database ServerAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create DB Link privilege with network access via Oracle Net to compromise RDBMS. Successful attacks… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Oracle Database ServerAIOracle NET ServicesAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services. Successful attacks of this vulnerability can… | |
| Aplazada | Alta (8.5) | 0.32% | — | Oracle Database ServerAIOracle TextAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Create Index privilege with network access via Oracle Net to compromise Oracle Text. While… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise RDBMS.… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Database ServerAI | 15/9/2026 | 17/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can… | |
| Aplazada | Alta (7.5) | 0.32% | — | Oracle Database ServerAIOracle XML Developers KITAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server. Supported versions that are affected are 19.3-19.32, 21.3-21.23 and 23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML… | |
| Pendiente de análisis | Alta (7.7) | 0.37% | — | Oracle Database ServerAI | 15/9/2026 | 16/9/2026 | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS. While the vulnerability is in RDBMS,… | |
| Pendiente de análisis | Alta (7.7) | 0.34% | — | Oracle Enterprise ManagerAIOracle DatabaseAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle… | |
| Aplazada | Media (6.5) | 0.36% | — | Oracle Database ServerAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Net Services component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Net Services. Successful attacks require human interaction from a… | |
| Aplazada | Media (6.9) | 0.61% | — | Ragic Enterprise Cloud DatabaseAI | 9/9/2026 | 9/9/2026 | The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files. | |
| Aplazada | Crítica (9.3) | 0.39% | — | Joodatabase LiteAI | 3/9/2026 | 3/9/2026 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors. | |
| Aplazada | Alta (8.2) | 0.41% | — | Tooljet DatabaseAI | 31/8/2026 | 10/9/2026 | ToolJet Database versions before v3.16.44 contain a privilege escalation vulnerability in the join_tables endpoint that grants JOIN_TABLES ability to all authenticated users without role or workspace membership validation. Attackers can read arbitrary ToolJet Database tables from any workspace by supplying victim… | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard Dimension Database ServerAI | 28/8/2026 | 28/8/2026 | A blind server-side request forgery (SSRF) vulnerability WatchGuard Dimension Database Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure SQL Database | 21/8/2026 | 4/9/2026 | Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.9) | 0.99% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (9.1) | 0.86% | — | Microsoft Azure SQL Database | 20/8/2026 | 24/8/2026 | Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (7.2) | 1.3% | — | Heimdall Data Database ProxyAI | 20/8/2026 | 1/9/2026 | Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this vulnerability. The specific flaw exists within the… |