Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.58% | — | Delphix Continous DataAI | 16/7/2026 | 16/7/2026 | A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter and lockout status were updated, defeating brute-force protections and enabling… | |
| Pendiente de análisis | Alta (8.7) | 0.40% | — | Delphix Continuous DataAI | 15/5/2026 | 17/6/2026 | Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host. | |
| Aplazada | Alta (8.5) | 0.36% | — | Delphiknight GEO TO LATAI | 13/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injection.This issue affects Geo to Lat: from n/a through <= 1.0.19. | |
| Analizada | Media (5.3) | 0.28% | — | Perforce Delphix Continuous Compliance | 20/12/2025 | 17/6/2026 | In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information… | |
| Aplazada | Media (5.4) | 0.31% | — | Delphix Data Control TowerAI | 29/7/2024 | 17/6/2026 | A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application. | |
| Aplazada | Alta (8.8) | 0.74% | — | Delphix EngineAI | 29/7/2024 | 17/6/2026 | Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE). | |
| Analizada | Media (4.2) | 0.34% | — | Jenkins Delphix | 6/3/2024 | 17/6/2026 | In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation. | |
| Analizada | Media (5.3) | 0.42% | — | Jenkins Delphix | 6/3/2024 | 17/6/2026 | In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default. | |
| Modificada | Media (6.5) | 0.95% | — | Jenkins Delphix | 16/8/2023 | 17/6/2026 | Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to. | |
| Modificada | Media (4.3) | 0.65% | — | Jenkins Delphix | 16/8/2023 | 17/6/2026 | A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Alta (7.8) | 0.27% | — | Jenkins Delphix | 16/10/2019 | 17/6/2026 | Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. | |
| Modificada | Media (6.8) | 2.8% | — | Embarcadero C++builder XE6Embarcadero Delphi XE6 | 6/10/2014 | 17/6/2026 | Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows context-dependent attackers to execute arbitrary code via the BITMAPINFOHEADER.biClrUsed field… | |
| Modificada | Media (6.8) | 5.7% | — | Embarcadero C++builder XE6Embarcadero Delphi XE6 | 15/9/2014 | 17/6/2026 | Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file. | |
| Modificada | Alta (7.5) | 3.4% | — | Borland Software C++ BuilderBorland Software C BuilderBorland Software DelphiBorland Software Developer Studio+2 | 1/12/2006 | 16/6/2026 | Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function. | |
| Modificada | Media (6.8) | 2.8% | — | Microchip Data Systems Ziptv FOR C++ BuilderMicrochip Data Systems Ziptv FOR Delphi 7Pentaware Pentasuite-proPentaware Pentazip | 8/9/2006 | 16/6/2026 | Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive… | |
| Modificada | Baja (2.1) | 0.77% | — | Delphiturk Codebank | 27/4/2005 | 16/6/2026 | DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges. | |
| Modificada | Baja (2.1) | 0.77% | — | Delphiturk FTP | 27/4/2005 | 16/6/2026 | DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges. |