Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2691 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.7) | — | — | Amazon Bedrock Agentcore Starter ToolkitAI | 6/10/2026 | 6/10/2026 | Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests… | |
| Recibida | Alta (8.8) | — | — | Amazon Bedrock Agentcore Starter ToolkitAI | 6/10/2026 | 6/10/2026 | Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated… | |
| Aplazada | Alta (8.5) | 0.29% | — | Udesign CoreAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in UDesign Core <= 4.15.0 versions. | |
| Aplazada | Crítica (10) | 0.29% | — | Doctreat CoreAI | 6/10/2026 | 6/10/2026 | Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. | |
| Aplazada | Media (5.1) | 0.54% | — | Nasa Core Flight SystemAI | 4/10/2026 | 6/10/2026 | A flaw has been found in NASA cFS up to 7.0.1. This issue affects the function CFE_FS_ParseInputFileNameEx of the file cfe/modules/fs/fsw/src/cfe_fs_api.c. This manipulation causes out-of-bounds read. Remote exploitation of the attack is possible. The pull request to fix this issue awaits acceptance. | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | — | Nasa-ammos Ait-coreAI | 3/10/2026 | 6/10/2026 | CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry… | |
| Pendiente de análisis | Alta (8.1) | 0.20% | — | Dogtagpki Pki-coreAI | 2/10/2026 | 6/10/2026 | A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Fortra Core Privileged Access ManagerAI | 1/10/2026 | 1/10/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Aplazada | Alta (8.8) | 0.23% | — | Bytecore MCP Connector FOR AI ToolsAI | 1/10/2026 | 1/10/2026 | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | |
| Aplazada | Alta (8.8) | 0.38% | — | Bytecore Stack MCP Connector FOR AI ToolsAI | 1/10/2026 | 3/10/2026 | The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's… | |
| En análisis | Crítica (9.3) | 0.29% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the attacker to gain full administrative… | |
| En análisis | Media (6.7) | 0.10% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Two Kiteworks Core cluster-management operations did not validate file paths supplied to them, so an attacker holding root on one node of a cluster could write files as root onto another node and cause them to be executed there. Exploitation requires backend root access on a cluster node and a pending software patch… | |
| En análisis | Media (5.4) | 0.21% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core did not apply its gateway-level API security controls to every request authenticated through the platform's central authentication service. An authenticated user could reach REST API functionality over a request path on which those controls, including enforcement of signed-out and revoked sessions, were… | |
| En análisis | Media (6.6) | 0.40% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | An optional, separately licensed repository-connector feature in Kiteworks Core did not neutralize special characters in a user-supplied path before passing it to an external command. An authenticated system administrator could inject additional commands and write arbitrary content to files owned by the service… | |
| En análisis | Alta (7.2) | 0.34% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | An administrative import function in Kiteworks Core did not verify that the requesting administrator was entitled to create the privileged integration credential being imported. A delegated administrator holding a single narrowly scoped administrative permission could therefore obtain full system administrator… | |
| En análisis | Alta (7.2) | 0.27% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned. An administrator whose delegated permissions covered role changes alone could therefore raise an account to full system-administrator privileges. | |
| En análisis | Alta (8.1) | 0.21% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an administrator holding only a single, narrowly scoped delegated permission to store crafted content that later executes arbitrary JavaScript in the authenticated session of a System Administrator who views the affected page. This could have… | |
| En análisis | Crítica (9.8) | 0.33% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user,… | |
| En análisis | Media (4.6) | 0.16% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core contains a business logic flaw in a Kiteworks file-request feature allowed an authenticated user to send a request that appeared to originate from another user, because the server did not verify that the requester was authorized to act as the specified account. This could be used to solicit files or… | |
| En análisis | Alta (8.1) | 0.31% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. A deserialization weakness in Kiteworks Core could, under certain conditions, allow crafted data to be deserialized unsafely, potentially resulting in remote code execution on the appliance. Exploitation depends on an attacker… | |
| En análisis | Alta (8.7) | 0.22% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an authenticated user to submit content that, when later viewed by another user, executes arbitrary JavaScript in that user's authenticated session. This could be… | |
| En análisis | Alta (7.2) | 0.64% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command… | |
| En análisis | Alta (7.2) | 0.33% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an… | |
| En análisis | Alta (7.2) | 1.1% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a configuration package whose contents were not sufficiently validated before being processed. A crafted package could cause the underlying system to execute arbitrary operating-system… | |
| En análisis | Alta (7.2) | 0.34% | — | Kiteworks CoreAI | 30/9/2026 | 1/10/2026 | Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role assignment, which could allow an authenticated administrative user with limited, non-Sysadmin role-management permissions to elevate another user to full system-administrator… |