Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
3950 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | — | — | Redhat Ansible PlatformAI | 6/10/2026 | 6/10/2026 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without… | |
| Aplazada | Alta (8.5) | 0.29% | — | Buddyboss PlatformAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Buddyboss Platform <= 3.1.0 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to access the complete device shadow of any device by specifying its device ID. This vulnerability exposes sensitive information, such as device credentials, owner details, network data, and telemetry,… | |
| Aplazada | Media (6.3) | 0.27% | — | Meari IOT Cloud PlatformAI | 2/10/2026 | 3/10/2026 | The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors,… | |
| Aplazada | Alta (7.4) | 0.16% | — | Havelsan SEF AI Chatbot PlatformAI | 2/10/2026 | 2/10/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Media (4.1) | 0.15% | — | Enocta PlatformAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes. This issue affects Enocta Platform: through 2026-09-28. | |
| Aplazada | Alta (8.1) | 0.26% | — | Enocta Educational Technologies INC Enocta PlatformAI | 28/9/2026 | 28/9/2026 | Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers. This issue affects Enocta Platform: through 2026-09-28. | |
| Pendiente de análisis | Alta (7.4) | 0.21% | — | Parseplatform Parse ServerAI | 27/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 < 9.10.1-alpha.10 and >= 8.0.2 < 8.6.91, the code-based authentication adapters (GitHub, Google Play Games, Instagram, LINE, LinkedIn, Microsoft, QQ, Spotify, WeChat, Weibo) verify the client's authorization code with the external provider on signup… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, LiveQuery evaluates the protectedFields class-level permission against an incompletely resolved caller identity: the subscriber's roles are not resolved, and when a subscription does not supply its own… | |
| Pendiente de análisis | Alta (8.7) | 0.36% | — | Parseplatform Parse ServerAI | 26/9/2026 | 30/9/2026 | Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device token deduplication logic for installation records does not validate the type of client-supplied installation fields before using them to build database queries. An unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Automation WEB PlatformAI | 25/9/2026 | 25/9/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and… | |
| Pendiente de análisis | Crítica (9.3) | 0.30% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security… | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security… | |
| Pendiente de análisis | Alta (8.4) | 0.24% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling… | |
| Pendiente de análisis | Crítica (9.3) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Pendiente de análisis | Media (6.8) | 0.45% | — | Redhat Ansible Automation PlatformAI | 24/9/2026 | 24/9/2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an… | |
| Pendiente de análisis | Alta (7.2) | 0.43% | — | Ansible Automation PlatformAIRsyslogAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config file… | |
| Pendiente de análisis | Media (6.6) | 0.29% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 26/9/2026 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command… | |
| Pendiente de análisis | Media (6.4) | 0.17% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 24/9/2026 | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback,… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST… | |
| Pendiente de análisis | Crítica (9.9) | 0.43% | — | Ansible Automation PlatformAIAnsible Automation-controllerAI | 23/9/2026 | 25/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that… | |
| Pendiente de análisis | Media (4.3) | 0.14% | — | Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled)… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a… | |
| Pendiente de análisis | Alta (7.6) | 0.31% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD,… |