CVE-2026-1622
Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files. The "obf...
Base de datos completa de CVEs, exploits de Exploit-DB y el catálogo KEV de CISA. Actualizada diariamente con las últimas vulnerabilidades.
787
2K+
1K+
EN VIVO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i...
The database account and password are hardcoded, allowing login with the account to manipulate the d...
A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentica...
Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to b...
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unaut...
Neo4j Enterprise and Community editions versions prior to 2026.01.3 and 5.26.21 are vulnerable to a potential information disclosure by a user who has ability to access the local log files. The "obf...
Stored Cross-Site Scripting (XSS) vulnerability type in Apidog in the version 2.7.15, where SVG image uploads are not properly sanitized. This allows attackers to embed malicious scripts in SVG files...
The SIBS woocommerce payment gateway plugin for WordPress is vulnerable to time-based SQL Injection via the ‘referencedId’ parameter in all versions up to, and including, 2.2.0 due to insufficient esc...
The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.3 due to insufficient escaping o...
The WP Content Permission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ohmem-message' parameter in all versions up to, and including, 1.2 due to insufficient input saniti...
The Smart Appointment & Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the saab_save_form_data AJAX action in all versions up to, and including, 1.0.7 due to insufficien...
| ID CVE | Proveedor | Producto | Fecha añadida | Ransomware |
|---|---|---|---|---|
| CVE-2026-20805 | Microsoft | Windows | 2026-01-13 | - |
| CVE-2025-8110 | Gogs | Gogs | 2026-01-12 | - |
| CVE-2025-37164 | Hewlett Packard Enterprise (HPE) | OneView | 2026-01-07 | - |
| CVE-2009-0556 | Microsoft | Office | 2026-01-07 | - |
| CVE-2025-14847 | MongoDB | MongoDB and MongoDB Server | 2025-12-29 | - |
Esta base de datos se proporciona únicamente con fines educativos y de investigación de seguridad autorizada.