Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.12% | — | Snowflake Python DriverAISnowflake GO DriverAISnowflake Jdbc DriverAISnowflake Node.js DriverAI+2 | 8/9/2026 | 10/9/2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did… | |
| Analizada | Media (6) | 0.37% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is enabled, and stems from the driver copying… | |
| Analizada | Alta (8.7) | 0.49% | — | Mongodb BI Connector Odbc Driver | 28/8/2026 | 11/9/2026 | A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its diagnostic message, memory adjacent to that… | |
| Analizada | Media (6.8) | 0.17% | — | Oracle Mysql Connector/odbc | 18/8/2026 | 2/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful… | |
| Analizada | Media (6.5) | 0.37% | — | Oracle Mysql Connector/odbc | 18/8/2026 | 2/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this… | |
| Analizada | Media (5.5) | 0.16% | — | Oracle Mysql Connector/odbc | 18/8/2026 | 2/9/2026 | Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that is affected is 26.7.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful… | |
| Analizada | Alta (8.4) | 0.21% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder selection handling, and is reached only when… | |
| Analizada | Alta (8.8) | 0.50% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored procedure. Triggering this issue requires connecting to an untrusted or impersonated database server that returns crafted metadata. This may result in process termination,… | |
| Analizada | Alta (8.8) | 0.40% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability to respond in its place, in order to… | |
| Analizada | Crítica (9.5) | 0.54% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's process, leading to abnormal termination and,… | |
| Analizada | Alta (7.1) | 0.32% | — | Mongodb BI Connector Odbc Driver | 12/8/2026 | 11/9/2026 | The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buffer. When an application reads a sufficiently large floating point value as text, the driver may write beyond the end of that buffer and corrupt adjacent memory. A user… | |
| Analizada | Media (6.3) | 0.20% | — | Mongodb Odbc DriverMongodb SQL Schema Builder CLI | 12/8/2026 | 29/9/2026 | MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may have an uncontrolled URI dispatched to… | |
| Pendiente de análisis | Alta (8.8) | 1.3% | — | LibsnowflakeclientAISnowflake PHP PDO DriverAISnowflake Odbc DriverAI | 24/7/2026 | 30/7/2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a… | |
| Analizada | Alta (8.5) | 0.33% | — | Guardsix LogpointGuardsix Odbc | 22/4/2026 | 17/6/2026 | An issue was discovered in guardsix (formerly Logpoint) ODBC Enrichment Plugins before 5.2.1 (5.2.1 is used in guardsix 7.9.0.0). A logic flaw allowed stored database credentials to be reused after modification of the target Host, IP address, or Port. When editing an existing Enrichment Source, previously stored… | |
| Analizada | Alta (7.3) | 1.1% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To remediate this issue,… | |
| Analizada | Alta (8.7) | 0.68% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the driver's parsing operations. To remediate this issue, users should… | |
| Analizada | Crítica (9.1) | 0.74% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users… | |
| Analizada | Crítica (9.1) | 0.36% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to… | |
| Analizada | Alta (7.1) | 0.51% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate this issue, users should upgrade to version 2.1.0.0. | |
| Analizada | Alta (7.3) | 0.33% | — | Amazon Athena Odbc | 3/4/2026 | 24/7/2026 | Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated… | |
| Aplazada | Alta (8.6) | 0.45% | — | Amazon Aurora PostgresqlAIAmazon Jdbc WrapperAIAmazon GO WrapperAIAmazon Nodejs WrapperAI+2 | 10/11/2025 | 17/6/2026 | An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the… | |
| Aplazada | Alta (8.8) | 0.17% | — | Mongodb BI Connector Odbc DriverAI | 23/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6. | |
| Aplazada | Alta (8.8) | 0.13% | — | Mongodb Atlas SQL Odbc DriverAI | 23/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0. | |
| Aplazada | Baja (3.3) | 0.16% | — | Snowflake Odbc DriverAI | 28/4/2025 | 17/6/2026 | In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of Sensitive Information into a Log File. | |
| Analizada | Alta (8.6) | 0.46% | — | Amazon Redshift Odbc Driver | 24/12/2024 | 17/6/2026 | A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0. |