Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
14.244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.41% | — | Flowiseai Flowise | 13/9/2026 | 16/9/2026 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The… | |
| Aplazada | Alta (8.1) | 0.16% | — | CrewaiAI | 13/9/2026 | 22/9/2026 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library… | |
| Aplazada | Media (5.5) | 0.65% | — | Cheshire-cat-ai Cheshire CAT AIAI | 13/9/2026 | 14/9/2026 | A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.9) | 0.76% | — | Simalexan Api-lambda-send-email-sesAI | 13/9/2026 | 14/9/2026 | A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | NodemailerAI | 13/9/2026 | 24/9/2026 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several… | |
| Analizada | Media (6.3) | 0.48% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known… | |
| Analizada | Media (6.1) | 0.37% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The… | |
| Analizada | Media (6) | 0.34% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain… | |
| Aplazada | Media (6.3) | 0.39% | — | AiosmtplibAI | 12/9/2026 | 23/9/2026 | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like AUTH, NOTIFY, or ORCPT to envelope… | |
| Aplazada | Media (6.3) | 0.22% | — | KimaiAI | 11/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly create or reuse a `Team`, add the current… | |
| Aplazada | Alta (8.3) | 0.15% | — | Chainguard ApkoAIChainguard MelangeAI | 11/9/2026 | 30/9/2026 | melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the actual package files that get… | |
| Aplazada | Media (5.3) | 0.35% | — | KimaiAI | 11/9/2026 | 23/9/2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is later rendered into an invoice PDF, such as `Customer.invoiceText`, the server-side… | |
| Aplazada | Alta (7.5) | 0.76% | — | AirsaneAI | 11/9/2026 | 30/9/2026 | AirSane is a SANE frontend, and a scanner server that supports Apple's AirScan protocol. Versions prior to 0.4.12 have a vulnerability in the custom HTTP server implementation of AirSane that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) via memory exhaustion (OOM). In httpserver.cpp, the… | |
| Aplazada | Crítica (9.8) | 0.58% | — | Xiongmai IP Camera Xm530AI | 11/9/2026 | 22/9/2026 | Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full administrative control over the camera. | |
| Aplazada | Crítica (9.8) | 0.77% | — | Xiongmai IP Camera Xm530AI | 11/9/2026 | 22/9/2026 | An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream… | |
| Aplazada | Alta (7.5) | 0.60% | — | Xiongmai Xm530AIXiongmai Sofia IPCAIXiongmai Happytime Rtsp ServerAI | 11/9/2026 | 22/9/2026 | An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthenticated attackers to access live H.264 video and G.711 audio feeds in cleartext over… | |
| Aplazada | Alta (7.5) | 0.74% | — | Xiongmai IP Camera Xm530AI | 11/9/2026 | 22/9/2026 | A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to cause a denial of service or potentially execute arbitrary code via a crafted SOAP… | |
| Aplazada | Alta (7.8) | 0.84% | — | Tubitak Bilgem Pardus Boot RepairAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8. | |
| Aplazada | Crítica (9.3) | 0.59% | — | TailwindcssAIGohugo HugoAI | 11/9/2026 | 24/9/2026 | Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the… | |
| Aplazada | Media (6.8) | 0.43% | — | AI BuilderAI | 11/9/2026 | 11/9/2026 | The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the… | |
| Aplazada | Alta (8.7) | 0.32% | — | Brainzcompany Zenius EMSAI | 11/9/2026 | 18/9/2026 | Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109). | |
| Aplazada | Alta (7.5) | 0.93% | — | AcymailingAI | 11/9/2026 | 11/9/2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary… | |
| Aplazada | Alta (8.4) | 0.87% | — | Tianxi AI Agent PC ApplicationAI | 10/9/2026 | 11/9/2026 | A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application. | |
| Aplazada | Media (5.4) | 0.23% | 💥 PoC | Fairsketch Rise CRMAI | 10/9/2026 | 22/9/2026 | FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client user who visits the store page, enabling session hijacking, account takeover, and… | |
| Analizada | Crítica (9.8) | 1.1% | — | Flowiseai Flowise | 10/9/2026 | 15/9/2026 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint |