Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.3)0.58%—Delphix Continous DataAI16/7/202616/7/2026
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter and lockout status were updated, defeating brute-force protections and enabling…
Pendiente de análisisAlta (8.7)0.40%—Delphix Continuous DataAI15/5/202617/6/2026
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.
AplazadaAlta (8.5)0.36%—Delphiknight GEO TO LATAI13/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in delphiknight Geo to Lat geo-to-lat allows Blind SQL Injection.This issue affects Geo to Lat: from n/a through <= 1.0.19.
AnalizadaMedia (5.3)0.28%—Perforce Delphix Continuous Compliance20/12/202517/6/2026
In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information…
AplazadaMedia (5.4)0.31%—Delphix Data Control TowerAI29/7/202417/6/2026
A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application.
AplazadaAlta (8.8)0.74%—Delphix EngineAI29/7/202417/6/2026
Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).
AnalizadaMedia (4.2)0.34%—Jenkins Delphix6/3/202417/6/2026
In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections fails to take effect until Jenkins is restarted when switching from disabled validation to enabled validation.
AnalizadaMedia (5.3)0.42%—Jenkins Delphix6/3/202417/6/2026
In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled by default.
ModificadaMedia (6.5)0.95%—Jenkins Delphix16/8/202317/6/2026
Jenkins Delphix Plugin 3.0.2 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Overall/Read permission to access and capture credentials they are not entitled to.
ModificadaMedia (4.3)0.65%—Jenkins Delphix16/8/202317/6/2026
A missing permission check in Jenkins Delphix Plugin 3.0.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
ModificadaAlta (7.8)0.27%—Jenkins Delphix16/10/201917/6/2026
Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (6.8)2.8%—Embarcadero C++builder XE6Embarcadero Delphi XE66/10/201417/6/2026
Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows context-dependent attackers to execute arbitrary code via the BITMAPINFOHEADER.biClrUsed field…
ModificadaMedia (6.8)5.7%—Embarcadero C++builder XE6Embarcadero Delphi XE615/9/201417/6/2026
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.
ModificadaAlta (7.5)3.4%—Borland Software C++ BuilderBorland Software C BuilderBorland Software DelphiBorland Software Developer Studio+21/12/200616/6/2026
Heap-based buffer overflow in Borland idsql32.dll 5.1.0.4, as used by RevilloC MailServer; 5.2.0.2 as used by Borland Developer Studio 2006; and possibly other versions allows remote attackers to execute arbitrary code via a long SQL statement, related to use of the DbiQExec function.
ModificadaMedia (6.8)2.8%—Microchip Data Systems Ziptv FOR C++ BuilderMicrochip Data Systems Ziptv FOR Delphi 7Pentaware Pentasuite-proPentaware Pentazip8/9/200616/6/2026
Heap-based buffer overflow in the TZipTV component in (1) ZipTV for Delphi 7 2006.1.26 and for C++ Builder 2006-1.16, (2) PentaZip 8.5.1.190 and PentaSuite-PRO 8.5.1.221, and possibly other products, allows user-assisted attackers to execute arbitrary code via an ARJ archive with a long header. NOTE: the ACE archive…
ModificadaBaja (2.1)0.77%—Delphiturk Codebank27/4/200516/6/2026
DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.
ModificadaBaja (2.1)0.77%—Delphiturk FTP27/4/200516/6/2026
DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.