Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
14.244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.58% | — | RepairbuddyAI | 10/9/2026 | 10/9/2026 | Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | Mailmunch Grow Your Email ListAI | 10/9/2026 | 10/9/2026 | Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. | |
| Aplazada | Media (6.5) | 0.44% | — | Kainelabs YouzifyAI | 10/9/2026 | 11/9/2026 | Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. | |
| Aplazada | Baja (0.9) | 0.17% | — | Proma-ai PromaAI | 10/9/2026 | 10/9/2026 | A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File Preview Service. Such manipulation of the argument file_path leads to path traversal. Local access is required to… | |
| Pendiente de análisis | Media (6.8) | 0.14% | — | Activecampaign GeneralAI | 9/9/2026 | 14/9/2026 | A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An… | |
| Pendiente de análisis | Crítica (9.9) | 0.86% | 💥 PoC | CpanelAICpanel EmailtrackAI | 9/9/2026 | 10/9/2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | |
| Aplazada | Alta (8.8) | 0.60% | — | ChainlitAI | 9/9/2026 | 9/9/2026 | Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious sessionId values that escape the upload directory and recursively delete arbitrary… | |
| Aplazada | Alta (7.7) | 0.21% | — | Redhat OpenshiftAIOpenai OperatorAI | 9/9/2026 | 9/9/2026 | A privilege-escalation issue in the Portworx Operator when deployed on Red Hat OpenShift (OCP). Only under specific conditions during the initial provisioning of a Portworx storage cluster, a user holding only limited, namespace-scoped permissions could cause the operator to grant broader access than intended,… | |
| Analizada | Crítica (9.8) | 7.5% | ⚠ Explotación activa💥 PoC | Checkpoint Gaia EmbeddedCheckpoint Gaia OS | 9/9/2026 | 23/9/2026 | Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Aplazada | Media (4.3) | 0.18% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Reservation SystemAI | 9/9/2026 | 9/9/2026 | Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation. This issue affects Library Reservation System: before v22.2. | |
| Aplazada | Alta (8.8) | 2.9% | 💥 Exploit | Newfold WP Module DataAINewfold WP Plugin Crazy DomainsAINewfold WP Plugin WEBAINewfold WP Plugin HostgatorAI+1 | 9/9/2026 | 9/9/2026 | Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request —… | |
| Aplazada | Alta (8.8) | 0.24% | — | Yith Woocommerce WaitlistAI | 9/9/2026 | 9/9/2026 | The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and… | |
| Aplazada | Media (4.9) | 0.31% | — | Mail MintAI | 9/9/2026 | 9/9/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Analizada | Media (4.8) | 0.08% | — | Samsung Visual Voicemail | 9/9/2026 | 23/9/2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. | |
| Aplazada | Media (5.1) | 0.34% | — | Tile-ai TilelangAI | 9/9/2026 | 9/9/2026 | A weakness has been identified in tile-ai tilelang up to 0.1.14. This impacts the function KernelCache._load_kernel_from_disk of the file tilelang/cache/kernel_cache.py of the component Kernel Cache. Executing a manipulation can lead to deserialization. The attack may be performed from remote. This patch is called… | |
| Analizada | Crítica (10) | 3.3% | — | Adobe Campaign | 8/9/2026 | 11/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation… | |
| Analizada | Alta (8) | 0.59% | — | Microsoft VM Repair | 8/9/2026 | 14/9/2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network. | |
| Aplazada | Media (6) | 0.43% | — | ASH AIAI | 8/9/2026 | 8/9/2026 | AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned records (replacing them with… | |
| Analizada | Crítica (9.1) | 0.38% | — | Apache-airflow-providers-fab | 8/9/2026 | 18/9/2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant**… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through… | |
| Aplazada | Crítica (9.8) | 1.8% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through… | |
| Aplazada | Alta (7.4) | 0.41% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Hitachi Cosminexus Component ContainerAI | 8/9/2026 | 8/9/2026 | Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10… |