Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.45% | — | Google Cloud LookerAI | 24/7/2026 | 27/7/2026 | A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted allows an attacker to execute arbitrary JavaScript leading to administrative account takeover using a maliciously crafted… | |
| Aplazada | Alta (7.5) | 0.24% | — | Teradata DriverAIGoogle LookerAI | 25/11/2025 | 17/6/2026 | A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Teradata driver parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for these. | |
| Aplazada | Alta (7.7) | 0.24% | — | Google LookerAIDenodoAI | 24/11/2025 | 17/6/2026 | A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, cause Looker to execute a malicious command. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted instances. No user action is required for… | |
| Aplazada | Alta (7.7) | 0.24% | — | Google LookerAIIBM DB2AI | 24/11/2025 | 17/6/2026 | A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML, cause Looker to execute a malicious command, due to inadequate filtering of the driver's parameters. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated… | |
| Aplazada | Alta (7.3) | 0.31% | — | Google LookerAI | 24/11/2025 | 17/6/2026 | An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would execute an attacker-supplied script. Exploitation required at least one Looker extension installed on the instance. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been… | |
| Aplazada | Crítica (9.2) | 0.46% | — | Google LookerAI | 20/11/2025 | 17/6/2026 | An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email address string normalization.Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted. | |
| Aplazada | Media (6) | 0.27% | — | Google LookerAI | 19/11/2025 | 17/6/2026 | The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connection name, which is a reserved internal name for Looker's internal MySQL database. The schemas parameter is vulnerable to SQL injection, enabling attackers to manipulate SELECT queries that are… | |
| Aplazada | Alta (7.1) | 0.25% | — | Google LookerAI | 19/11/2025 | 17/6/2026 | An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git directory deletion, leading to arbitrary command execution on the Looker instance. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already been mitigated for Looker-hosted… | |
| Aplazada | Alta (7.7) | 0.26% | — | Google Looker StudioAI | 10/11/2025 | 17/6/2026 | An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on the data source database due to the stored credentials attached to the report. This… | |
| Aplazada | Alta (7.3) | 0.25% | — | Google Looker StudioAIGoogle BigqueryAI | 10/11/2025 | 17/6/2026 | A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sources. By creating a malicious report with native functions enabled, and having the victim access the report, an attacker could execute injected SQL queries with the victim's permissions in BigQuery.… | |
| Aplazada | Alta (7.6) | 0.31% | — | Google Looker StudioAIGoogle BigqueryAI | 10/11/2025 | 17/6/2026 | A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject malicious SQL that would execute with the report owner's permissions. The vulnerability affected to reports with BigQuery as the data source. This vulnerability was patched on 21 July 2025, and no… | |
| Aplazada | Alta (7.1) | 1.3% | — | Google LookerAI | 10/11/2025 | 17/6/2026 | A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows an attacker with Developer permission to execute arbitrary shell commands when a user is deleted on the host system. Looker-hosted and Self-hosted were found to be vulnerable. This issue has already… | |
| Analizada | Alta (8.9) | 0.19% | — | Google Cloud Looker | 11/10/2024 | 17/6/2026 | An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that are hosted by Looker: Customer-hosted Looker instances were found to be vulnerable and must be upgraded. This vulnerability has been patched in… | |
| Analizada | Media (6.5) | 0.16% | — | Google Looker | 22/5/2024 | 17/6/2026 | An Insecure Direct Object Reference in Google Cloud's Looker allowed metadata exposure across authenticated Looker users sharing the same LookML model. |