Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.42% | — | Perl DBIAIPerl DBD DBMAIPerl MldbmAIPerl DBD GoferAI | 19/9/2026 | 22/9/2026 | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not… | |
| Aplazada | Crítica (9.8) | 0.67% | — | DBD PGAI | 23/8/2026 | 26/8/2026 | DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL,… | |
| Pendiente de análisis | Media (5.6) | 0.13% | — | Canonical SnapdAISystemd-userdbdAI | 21/7/2026 | 22/7/2026 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged… | |
| Aplazada | Alta (7.7) | 0.16% | — | Perl DBD FileAI | 14/7/2026 | 15/7/2026 | DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the… | |
| Modificada | Media (4.3) | 0.66% | — | Megaeis Dbd+ | 22/3/2023 | 17/6/2026 | An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive account information | |
| Modificada | Alta (8.1) | 0.69% | — | Megafeis Bofei Dbd+ | 21/3/2023 | 17/6/2026 | An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests. | |
| Modificada | Crítica (9.8) | 0.77% | — | Megafeis Bofei Dbd+ | 21/3/2023 | 17/6/2026 | An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism. | |
| Modificada | Alta (7.5) | 0.78% | — | Megafeis Bofei Dbd+ | 21/3/2023 | 17/6/2026 | An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy. | |
| Modificada | Media (6.1) | 1.2% | — | Dbdeployer | 21/12/2020 | 17/6/2026 | DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files external to the target. In such scenario, an attacker could induce dbdeployer to write into a system file, thus altering… | |
| Modificada | Crítica (9.8) | 1.6% | — | Dbd\ \ | 11/12/2019 | 17/6/2026 | SQL injection vulnerability in DBD::PgPP 0.05 and earlier | |
| Modificada | Media (5.9) | 2.2% | — | Dbd-mysql Project Dbd-mysql | 1/7/2017 | 17/6/2026 | The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related… | |
| Modificada | Crítica (9.8) | 4.6% | — | Dbd-mysql Project Dbd-mysql | 1/7/2017 | 17/6/2026 | The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free… | |
| Modificada | Media (5.9) | 2.4% | — | Dbd-mysql Project Dbd-mysql | 17/2/2017 | 17/6/2026 | The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression. | |
| Modificada | Alta (8.1) | 3.1% | — | Dbd-mysql Project Dbd-mysql | 29/11/2016 | 17/6/2026 | There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1. | |
| Modificada | Alta (7.5) | 3.8% | — | Dbd-mysql Project Dbd-mysqlDebian Linux | 5/10/2016 | 17/6/2026 | Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message. | |
| Modificada | Crítica (9.8) | 4.5% | — | Dbd-mysql Project Dbd-mysqlDebian Linux | 19/8/2016 | 17/6/2026 | Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login. | |
| Modificada | Crítica (9.8) | 6.0% | — | Debian LinuxDbd-mysql Project Dbd-mysql | 19/8/2016 | 17/6/2026 | Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection. | |
| Modificada | Alta (10) | 4.2% | — | Debian LinuxDebian Dbd-firebird | 14/4/2015 | 17/6/2026 | Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns. | |
| Modificada | Alta (7.5) | 1.1% | — | Hiroyuki Oyama Dbd\ | 4/11/2011 | 16/6/2026 | SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5) | 2.0% | — | Debian Libdbd-pg-perl | 30/4/2009 | 16/6/2026 | Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns. | |
| Modificada | Alta (7.5) | 4.3% | — | CMU Dbd\ | 30/4/2009 | 16/6/2026 | Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows. | |
| Modificada | Media (5) | 1.8% | — | Gnome Dhcdbd | 16/6/2006 | 16/6/2026 | Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption. | |
| Modificada | Alta (7.5) | 2.0% | — | Gracenote Cddbd | 26/11/1996 | 16/6/2026 | Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message. |