Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.40%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a code-related vulnerability in the GoldenDB database product. Attackers can access system tables to disrupt the normal operation of business SQL.
AnalizadaAlta (7.8)0.32%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.
AnalizadaAlta (7.5)0.36%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
AnalizadaAlta (7.5)0.36%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a SQL injection vulnerability in the GoldenDB database product. Attackers can inject commands to extract database information.
AnalizadaMedia (6.5)0.29%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is a Permission Management and Access Control vulnerability in the GoldenDB database product. Attackers can manipulate requests to bypass privilege restrictions and delete content.
AnalizadaAlta (7.5)0.38%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.
AnalizadaMedia (5.3)0.24%—ZTE Zxcloud Goldendb27/4/202517/6/2026
There is an information disclosure vulnerability in the GoldenDB database product. Attackers can exploit error messages to obtain the system's sensitive information.