Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
40.012 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.64% | — | Mooncake Transfer EngineAI | 1/10/2026 | 2/10/2026 | Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 2/10/2026 | : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63. | |
| Aplazada | Crítica (9.8) | 0.73% | — | Infiniflow RagflowAI | 1/10/2026 | 5/10/2026 | RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution | |
| Aplazada | Crítica (9.8) | 0.27% | — | Infiniflow RagflowAI | 1/10/2026 | 5/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | LangflowAI | 1/10/2026 | 5/10/2026 | langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Langchain ChatchatAI | 1/10/2026 | 5/10/2026 | The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory. | |
| Aplazada | Crítica (9.1) | 0.35% | — | Chatchat-space Langchain-chatchatAI | 1/10/2026 | 5/10/2026 | The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge… | |
| Aplazada | Crítica (9.1) | 0.14% | — | Chatchat-space Langchain-chatchatAI | 1/10/2026 | 7/10/2026 | The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames. | |
| Aplazada | Crítica (9.8) | 0.33% | — | DeeptutorAI | 1/10/2026 | 5/10/2026 | deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell commands in the service environment. | |
| Aplazada | Crítica (9.8) | 0.40% | — | DeeptutorAI | 1/10/2026 | 5/10/2026 | deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace. | |
| Aplazada | Crítica (9.1) | 0.28% | — | DeeptutorAI | 1/10/2026 | 5/10/2026 | deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted control files through the HTTP tutorbot file route. | |
| Aplazada | Crítica (9.1) | 0.26% | — | DeeptutorAI | 1/10/2026 | 5/10/2026 | DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content. | |
| Aplazada | Crítica (9.1) | 0.35% | — | Stitionai DevikaAI | 1/10/2026 | 5/10/2026 | In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially compromising the entire server. | |
| Aplazada | Crítica (9.4) | 0.34% | — | — | 1/10/2026 | 2/10/2026 | This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface between an attacker-controlled web page and… | |
| Pendiente de análisis | Crítica (9.4) | 0.18% | — | Teledyne Flir Aware2AI | 1/10/2026 | 2/10/2026 | Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation. | |
| Pendiente de análisis | Crítica (10) | 0.43% | — | Teledyne Flir Aware2AI | 1/10/2026 | 2/10/2026 | Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal. | |
| Aplazada | Crítica (9.6) | 0.22% | — | Getsimplecms Getsimple CMS CEAI | 1/10/2026 | 6/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a… | |
| Aplazada | Crítica (9.1) | 0.53% | — | Getsimple CMSAI | 1/10/2026 | 1/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written… | |
| Aplazada | Crítica (9.1) | 0.34% | — | Getsimple CMSAI | 1/10/2026 | 5/10/2026 | GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and… | |
| Pendiente de análisis | Crítica (9.4) | 0.14% | — | Teledyne Flir Aware2AI | 1/10/2026 | 2/10/2026 | Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic. | |
| Analizada | Crítica (9.8) | 2.2% | ⚠ Explotación activa💥 PoC | Fortinet Fortimail | 1/10/2026 | 7/10/2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system… | |
| Aplazada | Crítica (9) | 0.19% | — | Joyland AIAI | 1/10/2026 | 7/10/2026 | Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted… | |
| Aplazada | Crítica (9.2) | 0.34% | — | LaravelAI | 1/10/2026 | 5/10/2026 | The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the entire server environment, including all… | |
| Pendiente de análisis | Crítica (9.1) | 0.57% | — | Dhis2AI | 1/10/2026 | 2/10/2026 | DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions… | |
| Pendiente de análisis | Crítica (9.8) | 0.17% | — | AuthlibAI | 1/10/2026 | 5/10/2026 | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server… |