Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.25% | — | IBM Engineering Workflow Management | 22/6/2026 | 1/10/2026 | IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the… | |
| Analizada | Crítica (10) | 0.82% | — | Langflow | 22/6/2026 | 26/6/2026 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise | |
| Analizada | Media (5.4) | 0.23% | — | IBM Engineering Workflow Management | 22/6/2026 | 6/10/2026 | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… | |
| Aplazada | Alta (7.7) | 0.45% | — | Digiwin Easyflow .netAI | 22/6/2026 | 22/6/2026 | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in. | |
| Aplazada | Media (5.1) | 0.28% | — | Digiwin Easyflow .netAI | 22/6/2026 | 22/6/2026 | EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load. | |
| Analizada | Baja (1.9) | 0.28% | — | Langflow | 22/6/2026 | 26/6/2026 | A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Baja (2.1) | 0.49% | — | Flowiseai FlowiseAI | 22/6/2026 | 22/6/2026 | A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor… | |
| Aplazada | Media (6) | 0.37% | — | Flowiseai FlowiseAI | 20/6/2026 | 22/6/2026 | Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers can bypass password change verification and session invalidation by supplying a crafted password hash, establishing… | |
| Aplazada | Media (6.9) | 0.46% | — | Flowiseai FlowiseAI | 20/6/2026 | 22/6/2026 | Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An attacker can enumerate valid email addresses and harvest sensitive user data including user IDs, names, account status,… | |
| Analizada | Media (5.1) | 0.33% | — | Flowiseai Flowise | 20/6/2026 | 23/6/2026 | Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="javascript:alert(document.cookie)">) in a chat box, or by having a… | |
| Aplazada | Crítica (9.3) | 0.93% | — | Flowiseai FlowiseAI | 20/6/2026 | 22/6/2026 | Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allow-list of permitted variables and relies on vm2 for… | |
| Aplazada | Baja (2.2) | 0.09% | — | Github WorkflowsAI | 17/6/2026 | 22/6/2026 | The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location. | |
| Aplazada | Alta (7.2) | 0.24% | — | Mitsubishielectric Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Room AIR ConditionersAIMitsubishielectric Wireless LAN Adapters FOR Packaged AIR ConditionersAIMitsubishielectric RefrigeratorsAI+12 | 17/6/2026 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Room Air Conditioners (for Japan and outside Japan); Wireless LAN Adapters for Packaged Air Conditioners (for Japan and outside Japan); Refrigerators (for Japan); Heat Pump… | |
| Analizada | Crítica (9.1) | 0.88% | — | Apache-airflow-providers-sftp | 17/6/2026 | 17/6/2026 | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment… | |
| Aplazada | Media (6.5) | 0.22% | — | Wphowto Flowplayer Video PlayerAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. | |
| Analizada | Alta (8.1) | 0.44% | — | Langflow | 11/6/2026 | 17/6/2026 | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references. | |
| Analizada | Media (5.4) | 0.23% | — | Langflow Desktop | 11/6/2026 | 17/6/2026 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Crítica (9.4) | 0.35% | — | Google Dialogflow CXAI | 11/6/2026 | 17/6/2026 | A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potentially take over a GCP project using a maliciously crafted playbook import. This vulnerability was patched on 15 March… | |
| Analizada | Media (4.8) | 0.25% | — | Broadcom Spring WEB Flow | 11/6/2026 | 4/9/2026 | Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error details with input reflected from an attacker. Affected versions:… | |
| Analizada | Media (6.4) | 0.29% | — | Broadcom Spring WEB Flow | 11/6/2026 | 4/9/2026 | Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1. | |
| Analizada | Media (6.5) | 0.97% | — | Apache-airflow-providers-samba | 9/6/2026 | 23/7/2026 | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path outside the configured `destination_path`. An attacker able to write objects into the source GCS bucket — typically an… | |
| Aplazada | Alta (7.2) | 0.42% | — | Foliovision FV Flowplayer Video PlayerAI | 9/6/2026 | 23/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Alta (7.7) | 0.56% | — | Flowiseai Flowise | 8/6/2026 | 23/7/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2. | |
| Analizada | Alta (7.7) | 0.56% | — | Flowiseai Flowise | 8/6/2026 | 23/7/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2. | |
| Analizada | Alta (7.7) | 0.56% | — | Flowiseai Flowise | 8/6/2026 | 23/7/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This issue has been patched in version 3.1.2. |