Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.99% | — | Apache-airflow-providers-google | 6/7/2026 | 8/7/2026 | Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different… | |
| Pendiente de análisis | Media (4.8) | 0.31% | — | Uniflow Universal Login ManagerAI | 6/7/2026 | 6/7/2026 | uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). Exploitation requires administrative privileges and may disclose configuration data… | |
| Aplazada | Media (6.9) | 0.64% | — | Prospero Flow CRMAI | 3/7/2026 | 6/7/2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 allows a remote, authenticated attacker to delete arbitrary calendar events… | |
| Aplazada | Media (5.1) | 0.30% | — | Infiniflow RagflowAI | 2/7/2026 | 14/7/2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then renders that name into the "Rerun from… | |
| Analizada | Alta (8.7) | 0.43% | — | Progress Flowmon Anomaly Detection System | 2/7/2026 | 7/7/2026 | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detection System (ADS) may send specially crafted requests that could result in unauthorized access to application data and its modification. | |
| Analizada | Alta (8.7) | 0.32% | — | Progress Flowmon | 2/7/2026 | 6/7/2026 | In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive… | |
| Analizada | Alta (8.1) | 0.55% | — | Lfprojects Mlflow | 2/7/2026 | 6/7/2026 | In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they… | |
| Aplazada | Media (6.4) | 0.35% | — | Foliovision FV Flowplayer Video PlayerAI | 1/7/2026 | 1/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Crítica (9.3) | 0.53% | — | Flowiseai Flowise | 30/6/2026 | 6/7/2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because this default secret is publicly visible… | |
| Analizada | Media (6.9) | 0.18% | — | Flowiseai Flowise | 30/6/2026 | 6/7/2026 | Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise restrictive default CORS configuration… | |
| Analizada | Crítica (9.1) | 0.27% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for encryption at rest. | |
| Analizada | Crítica (9.9) | 0.53% | 💥 PoC | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement. | |
| Analizada | Crítica (9.8) | 0.69% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and system integrity. | |
| Analizada | Crítica (9.8) | 0.64% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields. | |
| Analizada | Crítica (9.8) | 0.52% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. | |
| Analizada | Alta (8.2) | 0.34% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make unvalidated HTTP requests to user-controlled URLs, bypassing SSRF protections introduced in version 1.9.3. An authenticated attacker can exploit this to… | |
| Analizada | Crítica (9.1) | 0.48% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to read build event data or cancel jobs using a valid job identifier, resulting in information disclosure and denial of service. | |
| Analizada | Media (6.5) | 0.25% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py ) due to a Time-of-Check/Time-of-Use (TOCTOU) race condition that can be exploited via DNS rebinding. | |
| Analizada | Crítica (9.6) | 0.35% | — | Langflow | 30/6/2026 | 11/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant… | |
| Analizada | Crítica (10) | 0.64% | 💥 PoC | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants… | |
| Analizada | Alta (8.5) | 0.31% | — | Langflow | 30/6/2026 | 2/7/2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects parameter and supplying a public URL that… | |
| Analizada | Baja (1.3) | 0.50% | — | Lfprojects Mlflow | 28/6/2026 | 1/7/2026 | A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such manipulation leads to missing authorization. It is possible to launch the attack remotely. A high complexity level is… | |
| Analizada | Baja (2.3) | 1.6% | 💥 Exploit | Flowiseai Flowise | 28/6/2026 | 6/7/2026 | Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses the NODE_OPTIONS denylist entry. An authenticated user who can configure a Custom MCP node can… | |
| Modificada | Alta (7.5) | 0.44% | — | Apache-airflow-providers-ftp | 26/6/2026 | 16/9/2026 | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or `FTPSFileTransmitOperator` to move files over FTPS exposed file… | |
| Modificada | Crítica (10) | 1.2% | 💥 PoC | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application files loaded at boot for remote code… |