Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
5391 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.33% | — | Autoship CloudAI | 6/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | |
| Aplazada | Media (6.5) | 0.28% | — | APP FOR CloudflareAI | 6/10/2026 | 6/10/2026 | Subscriber Broken Access Control in App for Cloudflare® <= 1.10.1 versions. | |
| Pendiente de análisis | Alta (7.6) | 0.35% | — | Cloudfoundry UAAAI | 6/10/2026 | 6/10/2026 | Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by presenting the user token as an OAuth 2.0 Bearer credential on a… | |
| Pendiente de análisis | Media (6.5) | 0.18% | — | Cloudfoundry UAAAI | 6/10/2026 | 6/10/2026 | Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenticated external-OIDC browser session, via submitting a UAA access… | |
| Aplazada | Alta (7.1) | 0.24% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry,… | |
| Aplazada | Media (6.3) | 0.27% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors,… | |
| Aplazada | Alta (8.7) | 0.55% | — | Inspur Haiyue HCM CloudAI | 30/9/2026 | 1/10/2026 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as… | |
| Pendiente de análisis | Alta (7.6) | 0.38% | — | CloudtakAI | 30/9/2026 | 30/9/2026 | CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to version 13.10.0, every route in the ESRI helper family (api/routes/esri.ts) takes a fully attacker-controlled URL from the request (POST /api/esri body url, and the portal / server / layer query parameters… | |
| Aplazada | Alta (8.8) | 0.48% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 30/9/2026 | 30/9/2026 | Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions. | |
| Analizada | Alta (8.8) | 0.57% | — | IBM Datastage ON Cloud PAK FOR Data | 29/9/2026 | 2/10/2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Fumasoft Fumeng CloudAI | 29/9/2026 | 30/9/2026 | Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unauthenticated remote attackers to inject arbitrary SQL through the Name parameter of the getEmpByname action without any authentication. Attackers can exploit UNION-based SQL injection techniques against the… | |
| Pendiente de análisis | Crítica (9.4) | 0.36% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 30/9/2026 | A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary code on the shared production servers using a specially crafted script bypassing… | |
| Pendiente de análisis | Alta (8.3) | 0.32% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 29/9/2026 | A Confused Deputy vulnerability in the EmailTask component in Google Cloud Application Integration versions prior to 2026-06-30 on Google Cloud Platform allows an authenticated attacker to read and exfiltrate arbitrary Google-internal files via a crafted attachment file path. This vulnerability was patched on 30 June… | |
| Pendiente de análisis | Crítica (9.4) | 0.24% | — | Google Cloud Application IntegrationAI | 28/9/2026 | 29/9/2026 | An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud user to execute arbitrary internal RPCs from inside Google's production network under a privileged identity using an… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 28/9/2026 | 28/9/2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 28/9/2026 | 1/10/2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available… | |
| Aplazada | Baja (2.1) | 0.30% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 28/9/2026 | 1/10/2026 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.26% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 28/9/2026 | A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting. The attack… | |
| Aplazada | Baja (2.1) | 0.28% | — | Vishalmathur Cloudclassroom-php-projectAI | 27/9/2026 | 30/9/2026 | A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 28/9/2026 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file updatedetailsfromfaculty.php. Such manipulation of the argument myfid leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.25% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 28/9/2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product… | |
| Aplazada | Baja (2.1) | 0.21% | — | Mathurvishal Cloudclassroom PHP ProjectAI | 27/9/2026 | 30/9/2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit is now public and may be used. This product does… | |
| Aplazada | Media (6.9) | 0.19% | — | CloudreveAI | 27/9/2026 | 28/9/2026 | Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads. | |
| Aplazada | Baja (2.3) | 0.22% | — | CloudreveAI | 27/9/2026 | 28/9/2026 | Cloudreve before 4.16.1 fails to properly sanitize file paths returned by remote downloaders, allowing authenticated users to create files outside the selected destination directory. Attackers can exploit path traversal sequences in downloader metadata to write files to unexpected locations within accessible… | |
| Aplazada | Media (5.3) | 0.19% | — | CloudreveAI | 27/9/2026 | 30/9/2026 | Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client that has been authorized by an administrator with only the… |