Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
14.243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.51% | 💥 PoC | Moonshot AI KimiAI | 18/9/2026 | 22/9/2026 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component | |
| Pendiente de análisis | Alta (7.5) | 0.44% | 💥 PoC | Apache AirflowAI | 18/9/2026 | 22/9/2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it — a state-changing action gated on a… | |
| Analizada | Crítica (9.8) | 0.67% | — | Microsoft Azure AI Foundry | 17/9/2026 | 25/9/2026 | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network. | |
| Analizada | Crítica (10) | 0.80% | — | Microsoft Azure Container Registry | 17/9/2026 | 29/9/2026 | Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.1) | 0.49% | 💥 PoC | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting… | |
| Aplazada | Alta (8.8) | 0.52% | 💥 PoC | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying… | |
| Pendiente de análisis | Media (6.1) | 0.33% | — | FairmailAI | 17/9/2026 | 23/9/2026 | FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incompletely sanitizes untrusted message HTML. For non-allowlisted hosts,… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Maildata Email Archiving SystemAI | 17/9/2026 | 22/9/2026 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. | |
| Aplazada | Alta (7.8) | 0.19% | — | SailAI | 17/9/2026 | 24/9/2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using the X11 one-byte-per-literal layout, but an X10 static short file causes the flat… | |
| Pendiente de análisis | Crítica (9.8) | 0.78% | — | SailAI | 17/9/2026 | 23/9/2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in Bitmap color mode to SAIL_PIXEL_FORMAT_BPP1_INDEXED without requiring the file… | |
| Aplazada | Crítica (9.8) | 0.78% | — | SailAI | 17/9/2026 | 24/9/2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-byte-per-pixel SAIL_PIXEL_FORMAT_BPP8_INDEXED format returned by… | |
| Aplazada | Baja (2.1) | 0.84% | — | Punchin-emailAICloudflare WorkersAI | 17/9/2026 | 30/9/2026 | punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent… | |
| Pendiente de análisis | Media (4.8) | 0.30% | — | Eclipse AnkaiosAI | 17/9/2026 | 18/9/2026 | In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs. | |
| Aplazada | Media (5.3) | 0.30% | — | Paidmembershipsincorporated Paid Memberships SubscriptionsAI | 17/9/2026 | 18/9/2026 | The Paid Membership Subscriptions WordPress plugin before 3.0.9 does not verify that the amount and currency reported by the payment provider match the pending payment before completing it, allowing unauthenticated users to obtain a paid membership by paying an arbitrary lower amount. | |
| Aplazada | Alta (8.1) | 0.91% | — | Paid DownloadsAI | 17/9/2026 | 19/9/2026 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin()… | |
| Pendiente de análisis | Alta (7.5) | 0.43% | — | Apple ContainerizationAI | 16/9/2026 | 18/9/2026 | A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in containerization version 0.41.0. | |
| Pendiente de análisis | Alta (8.3) | 0.40% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain… | |
| Pendiente de análisis | Alta (8.3) | 0.38% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the… | |
| Pendiente de análisis | Alta (8.7) | 0.82% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for… | |
| Pendiente de análisis | Media (6) | 0.29% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key,… | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | Jenkins Gradle PluginAIGradleAIJetbrains DevelocityAI | 16/9/2026 | 18/9/2026 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the Develocity access key configured in the… | |
| Aplazada | Media (5.3) | 0.16% | — | Sooma 2gen Brain StimulatorAI | 16/9/2026 | 18/9/2026 | In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters. | |
| Modificada | Media (6.5) | 0.81% | — | Apache-airflow-providers-akeyless | 16/9/2026 | 17/9/2026 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team,… | |
| Analizada | Alta (8.8) | 1.2% | — | Apache-airflow-providers-apache-kafka | 16/9/2026 | 18/9/2026 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer… | |
| Analizada | Alta (8.1) | 0.37% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the… |