Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

4530 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.26%—Redhat Ansible Automation PlatformAI23/9/202625/9/2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the…
Pendiente de análisisCrítica (9.1)0.41%—Redhat Ansible Automation PlatformAIRedhat AWXAI23/9/202624/9/2026
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate…
Pendiente de análisisCrítica (9.9)0.62%—Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI23/9/202624/9/2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"…
Pendiente de análisisAlta (7.7)0.38%—Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI23/9/202626/9/2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller…
Pendiente de análisisAlta (8.2)0.52%—Redhat Ansible Automation PlatformAI23/9/202624/9/2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the…
Pendiente de análisisCrítica (9.9)0.80%—Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI23/9/202624/9/2026
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback…
Pendiente de análisisMedia (4.1)0.26%—Redhat Ansible Automation PlatformAI23/9/202624/9/2026
—
Pendiente de análisisMedia (5.3)0.27%—Autonomy Logic Openplc 3AI22/9/202623/9/2026
Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.
Pendiente de análisisMedia (6.4)0.22%—NautobotAI22/9/202625/9/2026
Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under review, or the one-response-per-user restriction applied by the intended approve and…
Pendiente de análisisMedia (5.4)0.22%—NautobotAI22/9/202623/9/2026
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, and a user with dcim.add_modulefamily or dcim.change_modulefamily permission can…
AplazadaMedia (4.4)0.21%—Wp2social Auto PublishAI19/9/202621/9/2026
The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to…
AplazadaMedia (5.3)0.52%—Autobahn PythonAI18/9/202624/9/2026
Autobahn Python is a WebSocket and WAMP implementation for Python that supports Twisted and asyncio. Prior to 26.7.1, WebSocket endpoints that accept permessage-deflate and rely on maxMessagePayloadSize enforce that limit against the compressed frame length before inflation but do not recheck the decompressed message…
AplazadaMedia (6.4)0.25%—Auto Upload ImagesAI18/9/202618/9/2026
The Auto Upload Images plugin for WordPress is vulnerable to Limited Server-Side Request Forgery in all versions up to, and including, 3.3.2 via the downloadImage function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations…
AplazadaAlta (8.1)0.49%—AI Agent AutomationAI17/9/202624/9/2026
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting…
AplazadaAlta (8.8)0.52%—AI Agent AutomationAI17/9/202624/9/2026
AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying…
AplazadaMedia (6.5)0.27%—AutopayAI17/9/202618/9/2026
The Autopay WordPress plugin before 5.0.1 does not enforce the signature on one of its payment callbacks, allowing unauthenticated users to disclose and delete the stored payment parameters of other customers' orders.
AnalizadaAlta (7.5)0.19%—Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+37217/9/202622/9/2026
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
Pendiente de análisisAlta (7.1)0.36%—IBM Business Automation WorkflowAI15/9/202616/9/2026
IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource.
Pendiente de análisisMedia (5.4)0.17%—IBM Business Automation WorkflowAI15/9/202616/9/2026
IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls.
Pendiente de análisisMedia (6.5)0.22%—IBM Cloud PAK FOR Business AutomationAI15/9/202616/9/2026
IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive…
AnalizadaMedia (5.4)0.20%—IBM Cloud PAK FOR Business Automation15/9/202623/9/2026
IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
AnalizadaMedia (5.4)0.17%—IBM Cloud PAK FOR Business Automation15/9/202623/9/2026
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
AnalizadaMedia (5.4)0.17%—IBM Cloud PAK FOR Business Automation15/9/202623/9/2026
IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Pendiente de análisisMedia (6.5)0.22%—IBM Cloud PAK FOR Business AutomationAI14/9/202616/9/2026
IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.
Pendiente de análisisMedia (5.4)0.18%—IBM Cloud PAK FOR Business AutomationAI14/9/202616/9/2026
IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers.