Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.42%—Perl DBIAIPerl DBD DBMAIPerl MldbmAIPerl DBD GoferAI19/9/202622/9/2026
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not…
AplazadaCrítica (9.8)0.67%—DBD PGAI23/8/202626/8/2026
DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which is the size of the bare numeric symbol plus NULL. But for special literals NaN, Inf, +Inf, -Inf, Infinity, +Infinity, -Infinity it emits the literal surrounded by quotes plus NULL,…
Pendiente de análisisMedia (5.6)0.13%—Canonical SnapdAISystemd-userdbdAI21/7/202622/7/2026
An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-systemd (inherited via ) inadvertently permit strictly confined snap applications, which lack the privileged…
AplazadaAlta (7.7)0.16%—Perl DBD FileAI14/7/202615/7/2026
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the…
ModificadaMedia (4.3)0.66%—Megaeis Dbd+22/3/202317/6/2026
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows authenticated attacker to gain access to sensitive account information
ModificadaAlta (8.1)0.69%—Megafeis Bofei Dbd+21/3/202317/6/2026
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to unlock model(s) without authorization via arbitrary API requests.
ModificadaCrítica (9.8)0.77%—Megafeis Bofei Dbd+21/3/202317/6/2026
An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.
ModificadaAlta (7.5)0.78%—Megafeis Bofei Dbd+21/3/202317/6/2026
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker to gain access to sensitive account information via insecure password policy.
ModificadaMedia (6.1)1.2%—Dbdeployer21/12/202017/6/2026
DBdeployer is a tool that deploys MySQL database servers easily. In DBdeployer before version 1.58.2, users unpacking a tarball may use a maliciously packaged tarball that contains symlinks to files external to the target. In such scenario, an attacker could induce dbdeployer to write into a system file, thus altering…
ModificadaCrítica (9.8)1.6%—Dbd\ \11/12/201917/6/2026
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
ModificadaMedia (5.9)2.2%—Dbd-mysql Project Dbd-mysql1/7/201717/6/2026
The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related…
ModificadaCrítica (9.8)4.6%—Dbd-mysql Project Dbd-mysql1/7/201717/6/2026
The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free…
ModificadaMedia (5.9)2.4%—Dbd-mysql Project Dbd-mysql17/2/201717/6/2026
The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.
ModificadaAlta (8.1)3.1%—Dbd-mysql Project Dbd-mysql29/11/201617/6/2026
There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.
ModificadaAlta (7.5)3.8%—Dbd-mysql Project Dbd-mysqlDebian Linux5/10/201617/6/2026
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.
ModificadaCrítica (9.8)4.5%—Dbd-mysql Project Dbd-mysqlDebian Linux19/8/201617/6/2026
Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call to mysql_errno after a failure of my_login.
ModificadaCrítica (9.8)6.0%—Debian LinuxDbd-mysql Project Dbd-mysql19/8/201617/6/2026
Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary code via vectors related to a lost server connection.
ModificadaAlta (10)4.2%—Debian LinuxDebian Dbd-firebird14/4/201517/6/2026
Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns.
ModificadaAlta (7.5)1.1%—Hiroyuki Oyama Dbd\4/11/201116/6/2026
SQL injection vulnerability in DBD::mysqlPP 0.04 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (5)2.0%—Debian Libdbd-pg-perl30/4/200916/6/2026
Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.
ModificadaAlta (7.5)4.3%—CMU Dbd\30/4/200916/6/2026
Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.
ModificadaMedia (5)1.8%—Gnome Dhcdbd16/6/200616/6/2026
Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption.
ModificadaAlta (7.5)2.0%—Gracenote Cddbd26/11/199616/6/2026
Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.