Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.55%—StarrocksAI28/8/202623/9/2026
StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges can access full SQL text, execution plans, and profiling data from every query executed by other users, including…
AplazadaMedia (5.3)0.38%—StarrocksAI28/8/202623/9/2026
StarRocks through 4.0.13 contains an authentication bypass vulnerability in five REST handler classes that override execute() directly instead of implementing executeWithoutPassword(). Attackers can access six unauthenticated endpoints on the frontend HTTP port to disclose cluster topology, database metadata, JVM…
AplazadaAlta (7.1)0.53%—StarrocksAI26/8/202623/9/2026
StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, but visitDropMaterializedViewStatement returns immediately with a comment stating the check happens in execution logic.…
AplazadaMedia (6.4)0.40%—Apache KvrocksAI25/6/202625/6/2026
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
AplazadaCrítica (10)0.48%—Apache KvrocksAIRedis LUAAICjsonAI25/6/202625/6/2026
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
AplazadaMedia (5.5)0.33%—Apache KvrocksAI25/6/202625/6/2026
A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
AplazadaBaja (2.4)0.15%—Apache KvrocksAI25/6/202625/6/2026
Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
AplazadaCrítica (9.4)0.36%—Apache KvrocksAI25/6/202625/6/2026
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
AplazadaAlta (8.5)0.32%—Rockstargames Rockstar Games LauncherAI21/1/202617/6/2026
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.
AnalizadaMedia (5.3)0.30%—Apache Kvrocks28/11/202517/6/2026
Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
AnalizadaMedia (5.4)0.41%—Apache Kvrocks28/11/202517/6/2026
Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v2.13.0. Users are recommended to upgrade to version 2.14.0, which fixes the issue.
AnalizadaAlta (7.5)0.75%—Apache Kvrocks22/4/202517/6/2026
Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is out of range. This issue affects Apache Kvrocks: through 2.11.1. Users are recommended to…
AnalizadaMedia (6.5)0.81%—Apache Kvrocks7/2/202517/6/2026
A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks. Since Kvrocks didn't detect if "Host:" or "POST" appears in RESP requests, a valid HTTP request can also be sent to Kvrocks as a valid RESP request and trigger some database operations, which can be dangerous when it is chained with SSRF. It is…
AplazadaMedia (6.5)0.32%—Shenzhen Intellirocks Tech CO LTD Govee HomeAI27/1/202517/6/2026
An issue in Shenzhen Intellirocks Tech Co. Ltd Govee Home iOS 6.5.01 allows attackers to access sensitive user information via supplying a crafted payload.
AplazadaAlta (8.8)0.46%—ASD Com.rocks.video.downloaderAIGoogle AndroidAI7/11/202417/6/2026
The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity component.
AnalizadaAlta (8)0.24%—Strawberryrocks Strawberry25/9/202417/6/2026
Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as defined in the GraphQL multipart request specification was enabled by default in all Strawberry HTTP view integrations. This made all Strawberry HTTP view integrations vulnerable to cross-site request…
AnalizadaCrítica (9.8)0.60%—Microcks19/8/202417/6/2026
In Microcks before 1.10.0, the POST /api/import and POST /api/export endpoints allow non-administrator access.
ModificadaAlta (7.2)0.57%—Rocksolidplugins Bulletin29/3/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bulletin WordPress Announcement & Notification Banner Plugin – Bulletin.This issue affects WordPress Announcement & Notification Banner Plugin – Bulletin: from n/a through 3.8.5.
ModificadaCrítica (9.8)1.0%—Microcks4/12/202317/6/2026
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
ModificadaAlta (7.3)1.5%—Rockstargames Grand Theft Auto V22/1/202317/6/2026
Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.
ModificadaCrítica (9.8)2.1%—Sitecore Rocks29/5/201917/6/2026
The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious commands and code via the Sitecore Rocks Hard Rocks Service.
ModificadaBaja (3.6)0.31%—Artsoft Rocks'n'diamonds15/12/201116/6/2026
Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home directory.
ModificadaAlta (7.5)1.0%—Rocksalt International VP ASP25/1/200816/6/2026
SQL injection vulnerability in paypalresult.asp in VP-ASP Shopping Cart 6.50 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.6)0.93%—Rocks Clusters21/7/200616/6/2026
Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call.