Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.12% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI+2 | 8/9/2026 | 10/9/2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Snowflake Jdbc DriverAI | 4/9/2026 | 10/9/2026 | Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable… | |
| Pendiente de análisis | Alta (7.4) | 0.16% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI | 4/9/2026 | 10/9/2026 | Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated as transient. A man-in-the-middle… | |
| Pendiente de análisis | Crítica (9.4) | 0.45% | — | Google Cloud Bigquery Data Transfer ServiceAICdata Jdbc DriverAI | 26/8/2026 | 31/8/2026 | An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and escalate privileges in the tenant project… | |
| Analizada | Alta (8.2) | 0.24% | — | Postgresql Jdbc Driver | 6/7/2026 | 9/7/2026 | pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who… | |
| Pendiente de análisis | Crítica (9.2) | 0.71% | — | Amazon Redshift Jdbc DriverAI | 8/5/2026 | 17/6/2026 | An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context, provided a… | |
| Modificada | Alta (7.5) | 4.1% | — | Postgresql Jdbc Driver | 29/4/2026 | 11/9/2026 | pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Analizada | Alta (8.1) | 0.73% | — | Microsoft Jdbc Driver FOR SQL Server | 14/10/2025 | 17/6/2026 | Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network. | |
| Aplazada | Crítica (9.8) | 0.69% | — | H2o-3AIMysql Jdbc DriverAIOracle JDKAI | 2/9/2025 | 17/6/2026 | A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability allows remote code execution (RCE) due to improper validation of JDBC connection parameters when using a Key-Value format. The vulnerability is present in the MySQL JDBC… | |
| Analizada | Media (5.9) | 0.49% | — | Postgresql Jdbc Driver | 11/6/2025 | 17/6/2026 | pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as… | |
| Analizada | Alta (8.3) | 0.64% | — | Exasol Jdbc Driver | 19/3/2025 | 17/6/2026 | An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution. | |
| Aplazada | Alta (7.3) | 0.70% | — | Exasol Jdbc DriverAI | 17/12/2024 | 17/6/2026 | Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this vulnerability to achieve Remote Code… | |
| Aplazada | Crítica (10) | 0.78% | — | Amazon Jdbc Driver FOR RedshiftAI | 15/5/2024 | 17/6/2026 | The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection is possible when using the non-default connection property… | |
| Modificada | Crítica (9.8) | 4.8% | — | Postgresql Jdbc DriverFedoraproject Fedora | 19/2/2024 | 17/6/2026 | pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the… | |
| Modificada | Crítica (9.8) | 1.0% | — | IBM Informix Jdbc Driver | 28/6/2023 | 17/6/2026 | IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511. | |
| Modificada | Media (5.5) | 0.49% | — | Postgresql Jdbc DriverDebian Linux | 23/11/2022 | 17/6/2026 | pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is larger than 2k. This will create a temporary file which is readable… | |
| Modificada | Alta (8) | 2.2% | — | Postgresql Jdbc DriverDebian LinuxFedoraproject Fedora | 3/8/2022 | 17/6/2026 | PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement… | |
| Modificada | Alta (7.8) | 0.48% | — | Insightsoftware Magnitude Simba Amazon Redshift Jdbc Driver | 9/5/2022 | 17/6/2026 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift JDBC Driver 1.2.40 through 1.2.55 may allow a local user to execute code. NOTE: this is different from CVE-2022-29972. | |
| Modificada | Alta (7.8) | 0.48% | — | Insightsoftware Magnitude Simba Amazon Athena Jdbc Driver | 9/5/2022 | 17/6/2026 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena JDBC Driver 2.0.25 through 2.0.28 may allow a local user to execute code. NOTE: this is different from CVE-2022-29971. | |
| Modificada | Crítica (9.8) | 3.0% | — | Postgresql Jdbc DriverDebian Linux | 10/3/2022 | 17/6/2026 | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the… | |
| Modificada | Crítica (9.8) | 3.1% | — | Postgresql Jdbc DriverFedoraproject FedoraQuarkusDebian Linux | 2/2/2022 | 17/6/2026 | pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided… | |
| Modificada | Alta (7.7) | 4.1% | — | Postgresql Jdbc DriverQuarkusNetapp Steelstore Cloud Integrated StorageFedoraproject Fedora+1 | 4/6/2020 | 17/6/2026 | PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. | |
| Modificada | Alta (8.1) | 2.9% | — | Postgresql Jdbc DriverRedhat Enterprise Linux | 30/8/2018 | 17/6/2026 | A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate… |