Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

349 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.32%—WarehousepgAI28/9/202630/9/2026
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role…
AplazadaAlta (7.9)0.46%—ClickhouseAIDepomo ChartbrewAI21/9/202628/9/2026
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in server/sources/plugins/clickhouse/clickhouse.protocol.js calls applySqlVariables() from server/sources/shared/sql/sql.variables.js without…
AplazadaMedia (5.3)0.33%—OpenpanelAIClickhouseAI19/9/20262/10/2026
OpenPanel through 2.3.0 fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.
Pendiente de análisisAlta (8.9)0.51%—OpenmeterAIClickhouseAI16/9/202618/9/2026
SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service, via crafted user-controlled JSONPath values submitted to meters API.
Pendiente de análisisMedia (6.1)0.05%—ClickhouseAI27/8/202631/8/2026
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a…
Pendiente de análisisBaja (3.7)0.45%—LighthouseAI20/8/20263/9/2026
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to inject unauthorized EndpointSlices and…
AplazadaCrítica (9.9)0.48%—Warehouse CargoAI20/8/202620/8/2026
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
AnalizadaAlta (7.1)0.34%—Oracle Warehouse Management18/8/202624/8/2026
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management.…
AnalizadaAlta (7.5)0.41%—Oracle Warehouse Management18/8/202628/8/2026
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Warehouse Management.…
AnalizadaAlta (7.7)0.35%—Oracle Warehouse Management18/8/202628/8/2026
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Warehouse Management. While…
AnalizadaAlta (8.3)0.39%—Oracle Warehouse Management18/8/202624/8/2026
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management.…
AplazadaMedia (5.5)0.41%—Chiuwingyan HouseAI6/8/202612/8/2026
A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
AplazadaBaja (2.1)0.52%—Yeqifu WarehouseAI5/8/202612/8/2026
A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal. It is possible to initiate the attack…
RechazadaSin puntuar——ClickhouseAIPostgresqlAI29/7/20266/8/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the…
AplazadaCrítica (9.8)0.82%—HypequeryAIClickhouseAI28/7/20264/8/2026
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query parameters with a trailing backslash to escape the closing quote and inject…
AnalizadaAlta (8.8)0.43%—Oracle Warehouse Management21/7/20266/8/2026
Vulnerability in the Oracle Warehouse Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Warehouse Management.…
AplazadaAlta (7.1)0.40%—AptabaseAIClickhouseAI21/7/202623/7/2026
Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authenticated attackers to read event data across all tenants by injecting unsanitized filter parameters into Liquid SQL templates. Attackers can supply malicious values through EventName, CountryCode,…
ModificadaAlta (8.8)0.91%—Microsoft Fabric Data Warehouse14/7/202619/8/2026
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
AplazadaBaja (3.3)0.31%—Docker ComposeAIRedisAIKeydbAIDragonflyAI+47/7/20267/7/2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the…
AplazadaAlta (8.1)0.47%—LighthouseAI2/7/202630/9/2026
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
AnalizadaMedia (5.3)0.25%—IBM DB2IBM DB2 Warehouse22/6/202626/9/2026
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.
AnalizadaMedia (6.5)0.34%—IBM DB2IBM DB2 Warehouse22/6/202630/9/2026
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations and obtain sensitive information outside of their authority due to improper token validation.
AnalizadaMedia (6.5)0.42%—IBM DB2IBM DB2 Warehouse22/6/20261/10/2026
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to improper allocation of resources.
AplazadaBaja (2.1)0.32%—Montodel House-rental-managementAI21/6/202622/6/2026
A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may…
AplazadaMedia (5.5)0.41%—Montodel House-rental-managementAI21/6/202623/6/2026
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now…