Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
5399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.48% | — | Multicloud-operators SubscriptionAI | 12/8/2026 | 27/8/2026 | A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause the system to copy sensitive Secret… | |
| Pendiente de análisis | Media (6.4) | 0.33% | — | Multicloud-operators ChannelAI | 12/8/2026 | 5/9/2026 | A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system (namespaces). By exploiting this, an attacker can modify these Secrets in… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Mygardyn Cloud APIAI | 11/8/2026 | 1/9/2026 | The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings. | |
| Aplazada | Media (5.3) | 0.31% | — | Mira Cloud APIAI | 11/8/2026 | 1/9/2026 | The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device, allowing them to evade vendor-side… | |
| Analizada | Alta (8.8) | 0.80% | — | Microsoft Azure Cyclecloud | 11/8/2026 | 17/8/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Azure Cyclecloud | 11/8/2026 | 17/8/2026 | Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. | |
| Pendiente de análisis | Crítica (10) | 0.85% | 💥 PoC | SAP Commerce CloudAI | 11/8/2026 | 17/8/2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on… | |
| Aplazada | Alta (8.7) | 0.51% | — | Inventec Appliances Chiline CloudAI | 11/8/2026 | 26/8/2026 | Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data. | |
| Aplazada | Media (5.1) | 0.30% | — | TinymceAIFit2cloud SqlbotAI | 10/8/2026 | 23/9/2026 | SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders TinyMCE output via v-html without sanitization. Attackers who can modify dashboard text widget content can inject arbitrary HTML and JavaScript that executes for all users… | |
| Aplazada | Baja (2.1) | 0.37% | — | Aliyun Alibabacloud-dataworks-mcp-serverAI | 9/8/2026 | 12/8/2026 | A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceRequestSchema of the file src/resources/initResources.ts. The manipulation of the argument request.params.uri results in server-side request forgery. The attack may be launched… | |
| Aplazada | Media (5.3) | 0.16% | — | Simple Captcha With Cloudflare TurnstileAI | 7/8/2026 | 26/8/2026 | The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache to the single-use challenge token in its Forminator integration, instead keying it to an attacker-controlled, reusable request value, allowing unauthenticated attackers to solve one challenge and… | |
| Pendiente de análisis | Media (4.2) | 0.21% | — | Cloudfoundry Bosh AgentAI | 6/8/2026 | 18/8/2026 | Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0… | |
| Analizada | Media (6.5) | 0.33% | — | Cisco RoomosCisco Roomos Cloud | 5/8/2026 | 17/8/2026 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then… | |
| Aplazada | Baja (1.9) | 0.16% | — | Epsilla Cloud VectordbAI | 5/8/2026 | 12/8/2026 | A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for unusual conditions. The attack needs to… | |
| Aplazada | Baja (2.1) | 0.43% | — | Kodcloud KodboxAI | 4/8/2026 | 12/8/2026 | A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. The manipulation of the argument callbackUrl leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (5.5) | 0.48% | — | Kodcloud KodboxAI | 4/8/2026 | 12/8/2026 | A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of the component msgWarning Plugin. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been published… | |
| Aplazada | Crítica (9.6) | 0.45% | — | Banzaicloud Vault Secrets WebhookAI | 31/7/2026 | 10/9/2026 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and… | |
| Aplazada | Media (6.3) | 0.31% | — | CloudreveAI | 31/7/2026 | 8/9/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI viewer with a view session to forge the token suffix and invoke WOPI… | |
| Aplazada | Alta (7.1) | 0.34% | — | CloudreveAI | 31/7/2026 | 8/9/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even though GetOauthRedirectService persists caller-supplied OneDrive secret and app_id values, allowing an OAuth token without Admin.Write to modify storage policy… | |
| Aplazada | Media (4.3) | 0.33% | — | CloudreveAI | 31/7/2026 | 8/9/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, a single-file share event-stream subscription resolves the share root to the owner’s parent folder and subscribes to that folder topic, allowing an authenticated share recipient to receive names, paths, rename targets, event types, and… | |
| Aplazada | Media (6.5) | 0.53% | — | CloudreveAI | 31/7/2026 | 8/9/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed file size but do not limit decoded pixel dimensions, allowing an authenticated user to submit a small PNG, JPEG, or GIF that triggers an unbounded allocation and terminates… | |
| Aplazada | Media (4.3) | 0.36% | — | CloudreveAI | 31/7/2026 | 8/9/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate email addresses and profile metadata for inactive or banned accounts.… | |
| Aplazada | Media (4.3) | 0.38% | — | CloudreveAI | 31/7/2026 | 8/9/2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file directory and create or conditionally overwrite files elsewhere in… | |
| Aplazada | Crítica (9.9) | 0.78% | — | Banzai Cloud Logging OperatorAI | 29/7/2026 | 10/9/2026 | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/model/render/fluent.go writes CRD strings such as Flow record_transformer.records values directly into fluent.conf without escaping, allowing a… | |
| Analizada | Alta (7.5) | 0.38% | — | IBM Cloud PAK System | 28/7/2026 | 19/8/2026 | IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files. |