Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.26% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 25/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the… | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | — | Redhat Ansible Automation PlatformAIRedhat AWXAI | 23/9/2026 | 24/9/2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate… | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"… | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller… | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Media (5.3) | 0.27% | — | Autonomy Logic Openplc 3AI | 22/9/2026 | 23/9/2026 | Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. | |
| Pendiente de análisis | Media (6.4) | 0.22% | — | NautobotAI | 22/9/2026 | 25/9/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and… | |
| Pendiente de análisis | Media (5.4) | 0.22% | — | NautobotAI | 22/9/2026 | 23/9/2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can… | |
| Aplazada | Media (4.4) | 0.21% | — | Wp2social Auto PublishAI | 19/9/2026 | 21/9/2026 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (5.3) | 0.52% | — | Autobahn PythonAI | 18/9/2026 | 24/9/2026 | Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message… | |
| Aplazada | Media (6.4) | 0.25% | — | Auto Upload ImagesAI | 18/9/2026 | 18/9/2026 | The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations… | |
| Aplazada | Alta (8.1) | 0.49% | — | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting… | |
| Aplazada | Alta (8.8) | 0.52% | — | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying… | |
| Aplazada | Media (6.5) | 0.27% | — | AutopayAI | 17/9/2026 | 18/9/2026 | The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 15/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive… | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. |