Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
14.243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.0% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that… | |
| Analizada | Crítica (9.1) | 0.81% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same… | |
| Analizada | Crítica (9.1) | 0.83% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches… | |
| Pendiente de análisis | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of… | |
| Aplazada | Alta (7.2) | 0.46% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks of… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful attacks… | |
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle E-business SuiteAIOracle Depot RepairAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair. Successful… | |
| Pendiente de análisis | Alta (8.5) | 0.40% | — | Oracle E-business SuiteAIOracle Complex Maintenance Repair AND OverhaulAI | 15/9/2026 | 22/9/2026 | Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex… | |
| Pendiente de análisis | Media (5.1) | 0.26% | — | Kidocode Crawl4aiAI | 15/9/2026 | 17/9/2026 | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled page content like the page title to… | |
| Pendiente de análisis | Alta (8.3) | 0.35% | — | Kidocode Crawl4aiAI | 15/9/2026 | 16/9/2026 | Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use DNS rebinding to access internal… | |
| Pendiente de análisis | Media (5.1) | 0.24% | — | Kidocode Crawl4aiAI | 15/9/2026 | 17/9/2026 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for… | |
| Pendiente de análisis | Alta (8.7) | 0.46% | — | Kidocode Crawl4aiAI | 15/9/2026 | 16/9/2026 | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any… | |
| Pendiente de análisis | Alta (7.6) | 0.37% | — | CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as… | |
| Pendiente de análisis | Alta (8.3) | 0.46% | — | Flowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | Flowiseai FlowiseAI | 15/9/2026 | 16/9/2026 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform… | |
| Pendiente de análisis | Alta (7.6) | 0.35% | — | Flowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from… | |
| Pendiente de análisis | Crítica (9) | 0.73% | — | Flowiseai FlowiseAI | 15/9/2026 | 16/9/2026 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute… | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | Sakailms SakaiAI | 15/9/2026 | 25/9/2026 | Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to… | |
| Pendiente de análisis | Media (4.8) | 0.15% | — | Lfprojects ApptainerAI | 15/9/2026 | 25/9/2026 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also authorizes a sibling path such as /data/safe-but-unsafe. A local user can consequently… | |
| Pendiente de análisis | Media (4.4) | 0.17% | — | Containers StorageAI | 15/9/2026 | 2/10/2026 | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer. | |
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Kidocode Crawl4aiAI | 15/9/2026 | 19/9/2026 | Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or page limits, exhausting disk, CPU, and… | |
| Aplazada | Alta (8.7) | 0.47% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection. |