Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
14.243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.39% | — | Flowiseai FlowiseAI | 15/9/2026 | 19/9/2026 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts. | |
| Aplazada | Crítica (9) | 0.68% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server. | |
| Aplazada | Alta (7.7) | 0.40% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by… | |
| Aplazada | Alta (7.6) | 0.35% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets. | |
| Aplazada | Crítica (9.9) | 0.43% | 💥 PoC | KaitenAI | 15/9/2026 | 22/9/2026 | kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Praisonai PlatformAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.77% | — | Praisonai PlatformAI | 15/9/2026 | 17/9/2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote… | |
| Aplazada | Crítica (9.8) | 0.74% | — | PraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist can be bypassed with Function('return this')() to recover the global object and… | |
| Aplazada | Crítica (9.4) | 0.64% | — | Praisonai AgentosAIPraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent… | |
| Aplazada | Crítica (9.8) | 0.75% | — | PraisonaiAI | 15/9/2026 | 17/9/2026 | PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or authorization. Any network client that can reach the port can call tools/list,… | |
| Aplazada | Crítica (9.9) | 0.73% | — | PraisonaiAI | 15/9/2026 | 17/9/2026 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require properties. Code can use… | |
| Aplazada | Alta (8.8) | 0.51% | — | PraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped AI SDK executes tool handlers during generation, a callback that returns false… | |
| Aplazada | Alta (8.8) | 0.55% | — | PraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExecutor passes the complete command string to sh -c. A command beginning with an… | |
| Aplazada | Alta (7.6) | 0.42% | — | PraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs… | |
| Aplazada | Alta (8.2) | 0.41% | — | PraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling… | |
| Aplazada | Alta (8.8) | 0.80% | — | PraisonaiAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the complete original string to child_process.exec(). A string that starts with an allowed… | |
| Aplazada | Alta (8.3) | 0.22% | — | PraisonaiagentsAIPraisonaiAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication… | |
| Aplazada | Media (5.3) | 0.46% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportController::editExportTemplate() inherit only the class-level create_export permission, which ROLE_TEAMLEAD receives by default, and omit the create_export_template permission required by the API… | |
| Aplazada | Alta (7.1) | 0.58% | — | KimaiAI | 15/9/2026 | 30/9/2026 | Kimai is an open-source time tracking application. Prior to 2.59.0, the KIMAI_SESSION cookie issued after password verification but before TOTP completion is accepted by every /api route because config/packages/security.yaml protects the API with IS_AUTHENTICATED and App\API\Authentication\ApiRequestMatcher routes an… | |
| Aplazada | Media (5.3) | 0.43% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the attacker-selected child rate identifier without… | |
| Aplazada | Media (5.3) | 0.45% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the referenced Activity. A teamlead can add users… | |
| Aplazada | Crítica (9.1) | 1.3% | 💥 Exploit | KimaiAI | 15/9/2026 | 30/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as kernel.secret. An unauthenticated attacker who… | |
| Aplazada | Media (5.3) | 0.30% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations through GET requests without a request-forgery defense. A remote… | |
| Aplazada | Media (5.3) | 0.46% | — | KimaiAI | 15/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or activity has been revoked. TimesheetVoter… | |
| Aplazada | Media (5.3) | 0.43% | — | KimaiAI | 15/9/2026 | 30/9/2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the supplied Project or Customer object. A user… |