Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.23% | — | Ondata Ckan MCP ServerAI | 21/9/2026 | 24/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS. Any caller-supplied `server_url` whose hostname *resolves* to an internal… | |
| Aplazada | Media (5.7) | 0.38% | — | Ckan MCP ServerAI | 21/8/2026 | 9/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A fix was applied to filter out ip… | |
| Aplazada | Media (6.5) | 0.19% | — | Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by buildCacheKey to collide and an attacker to prime… | |
| Aplazada | Media (5.3) | 0.38% | — | Ondata Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for dati.gov.it, allowing suffix-host and URL-userinfo… | |
| Aplazada | Baja (3.7) | 0.36% | — | Ckan MCP ServerAI | 14/8/2026 | 18/9/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a host that returns a non-CKAN response,… | |
| Analizada | Media (6.7) | 0.41% | — | Okfn Ckan | 13/5/2026 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authorization in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in… | |
| Analizada | Alta (8.3) | 2.2% | — | Okfn Ckan | 13/5/2026 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in order to gain access to private resources and PostgreSQL system information This vulnerability is fixed in 2.10.10 and… | |
| Analizada | Media (6.1) | 0.14% | — | Okfn Ckan | 13/5/2026 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests marked the endpoint as not requiring CSRF protection. The marking was a member variable in flask-wtf.csrf.CSRFProtect(), which was stored… | |
| Analizada | Media (6.6) | 0.21% | — | Okfn Ckan | 13/5/2026 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks. This vulnerability is fixed in 2.10.10 and 2.11.5. | |
| Analizada | Media (5.7) | 0.30% | — | Ondata Ckan MCP Server | 20/3/2026 | 17/6/2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Versions prior to 0.4.85 provide tools including ckan_package_search and sparql_query that accept a base_url parameter, making HTTP requests to arbitrary endpoints without restriction. A CKAN portal client has no legitimate reason to contact cloud metadata… | |
| Aplazada | Media (6.1) | 0.30% | — | Okfn CkanAI | 29/10/2025 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4, session ids could be fixed by an attacker if the site is configured with server-side session storage (CKAN uses cookie-based session storage by default). The attacker would need to either set a… | |
| Aplazada | Media (6.3) | 0.23% | — | Okfn CkanAI | 29/10/2025 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.9 and 2.11.4, the helpers.markdown_extract() function did not perform sufficient sanitization of input data before wrapping in an HTML literal element. This helper is used to render user-provided data on dataset,… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Clickandpledge Click AND Pledge ConnectAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Pledge Connect: from 25.04010101 through WP6.8. | |
| Aplazada | Crítica (9.3) | 0.43% | — | Clickandpledge Click Pledge WpjobboardAI | 10/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge WordPress-WPJobBoard click-pledge-wpjobboard allows Blind SQL Injection.This issue affects WordPress-WPJobBoard: from n/a through <= 25.07010000-WP6.8.1-JB5.11.5. | |
| Aplazada | Alta (7.2) | 0.51% | — | Clickandpledge Click AND Pledge ConnectAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect Plugin allows SQL Injection. This issue affects Click & Pledge Connect Plugin: from 2.24080000 through WP6.6.1. | |
| Modificada | Media (6.1) | 0.15% | — | Blackandwhitedigital Bookpress | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Black and White BookPress – For Book Authors book-press allows Cross-Site Scripting (XSS).This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7. | |
| Modificada | Crítica (9.8) | 0.47% | — | Blackandwhitedigital Bookpress | 7/2/2025 | 17/6/2026 | Missing Authorization vulnerability in Black and White BookPress – For Book Authors book-press allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BookPress – For Book Authors: from n/a through <= 1.2.7. | |
| Aplazada | Alta (7.3) | 0.46% | — | Okfn CkanAI | 5/2/2025 | 17/6/2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Using a specially crafted file, a user could potentially upload a file containing code that when executed could send arbitrary requests to the server. If that file was opened by an administrator, it could lead to escalation of… | |
| Analizada | Media (6.5) | 0.37% | — | Okfn Ckan | 21/8/2024 | 17/6/2026 | CKAN is an open-source data management system for powering data hubs and data portals. There are a number of CKAN plugins, including XLoader, DataPusher, Resource proxy and ckanext-archiver, that work by downloading the contents of local or remote files in order to perform some actions with their contents (e.g.… | |
| Analizada | Media (6.1) | 0.40% | — | Okfn Ckan | 21/8/2024 | 17/6/2026 | CKAN is an open-source data management system for powering data hubs and data portals. The Datatables view plugin did not properly escape record data coming from the DataStore, leading to a potential XSS vector. Sites running CKAN >= 2.7.0 with the datatables_view plugin activated. This is a plugin included in CKAN… | |
| Analizada | Media (5.3) | 0.38% | — | Okfn Ckan | 21/8/2024 | 17/6/2026 | CKAN is an open-source data management system for powering data hubs and data portals. If there were connection issues with the Solr server, the internal Solr URL (potentially including credentials) could be leaked to package_search calls as part of the returned error message. This has been patched in CKAN 2.10.5 and… | |
| Analizada | Media (5.3) | 0.44% | — | Okfn Ckan | 13/3/2024 | 17/6/2026 | A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This could lead to an attacker injecting false log entries or corrupt the log file format. This has been fixed in the CKAN versions 2.9.11 and 2.10.4. Users are advised to upgrade. Users unable to… | |
| Modificada | Media (6.5) | 0.58% | — | Okfn Ckan | 13/12/2023 | 17/6/2026 | CKAN is an open-source data management system for powering data hubs and data portals. Starting in version 2.0.0 and prior to versions 2.9.10 and 2.10.3, when submitting a POST request to the `/dataset/new` endpoint (including either the auth cookie or the `Authorization` header) with a specially-crafted field, an… | |
| Modificada | Alta (8.8) | 0.79% | — | Okfn Ckan | 30/5/2023 | 17/6/2026 | CKAN is an open-source data management system for powering data hubs and data portals. Prior to versions 2.9.9 and 2.10.1, the `ckan` user (equivalent to www-data) owned code and configuration files in the docker container and the `ckan` user had the permissions to use sudo. These issues allowed for code execution or… | |
| Modificada | Crítica (9.8) | 1.7% | — | Okfn Ckan | 26/5/2023 | 17/6/2026 | CKAN is an open-source data management system for powering data hubs and data portals. Multiple vulnerabilities have been discovered in Ckan which may lead to remote code execution. An arbitrary file write in `resource_create` and `package_update` actions, using the `ResourceUploader` object. Also reachable via… |