Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

2654 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisCrítica (9.9)0.59%—LangflowAI5/10/20266/10/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with…
En análisisAlta (7.1)0.25%—LangflowAI5/10/20266/10/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.6.8 until 1.9.1, Langflow authenticated access to the project identifier in a project-scoped MCP connection but did not authorize the resource URI supplied to resources/read. read_resource forwarded the attacker-controlled URI to…
En análisisMedia (5.4)0.18%—LangflowAI5/10/20266/10/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/build/{flow_id}/vertices/{vertex_id} handlers. Through version 1.7.1, an unauthenticated caller who…
En análisisCrítica (9.9)0.40%—LangflowAILangflow-baseAILangflow LFXAI5/10/20266/10/2026
Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server…
AplazadaCrítica (9.8)0.73%—Infiniflow RagflowAI1/10/20265/10/2026
RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution
AplazadaMedia (6.5)0.18%—Infiniflow RagflowAI1/10/20265/10/2026
infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
AplazadaMedia (6.5)0.18%—Infiniflow RagflowAI1/10/20262/10/2026
Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
AplazadaMedia (6.5)0.16%—Infiniflow RagflowAI1/10/20265/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AplazadaCrítica (9.8)0.27%—Infiniflow RagflowAI1/10/20265/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AplazadaMedia (6.5)0.23%—Infiniflow RagflowAI1/10/20265/10/2026
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.
Pendiente de análisisAlta (7.5)0.56%—LangflowAI1/10/20266/10/2026
langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack…
Pendiente de análisisCrítica (9.8)0.40%—LangflowAI1/10/20265/10/2026
langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: HTTP or browser-backed service path. A…
Pendiente de análisisMedia (5.3)0.36%—VaadinAIVaadin Spreadsheet FlowAIVaadin SpreadsheetAI30/9/202630/9/2026
A missing authorization check in the Vaadin Spreadsheet component allows an authenticated user of an application that renders a spreadsheet to add or replace cell comments on a sheet that has protection enabled, including on cells that are locked. Writing a comment to a cell that does not exist yet also creates the…
Pendiente de análisisMedia (6.3)0.47%—VaadinAIVaadin CoreAIVaadin Charts FlowAIVaadin ChartsAI+130/9/202630/9/2026
A prototype pollution vulnerability exists in the deep merge helpers of Vaadin Charts and Vaadin Component Base. Merging an object the application does not control into a chart configuration or into a component's i18n property writes onto Object.prototype, making the injected properties visible to every object in the…
AplazadaAlta (8.8)0.54%—CartflowsAI30/9/202630/9/2026
Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions.
AplazadaMedia (5.1)0.20%—Digiwin Easyflow .netAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
AplazadaCrítica (9.3)0.43%—Digiwin Easyflow DOT NETAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.
AplazadaAlta (7.1)0.38%—Digiwin EasyflowAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.
AplazadaAlta (7.1)0.27%—Digiwin EasyflowAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
AplazadaCrítica (9.3)0.51%—Digiwin EasyflowAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
AplazadaAlta (8.6)0.56%—Digiwin EasyflowAI30/9/202630/9/2026
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AplazadaMedia (5.5)0.25%—Risesoft Y9 Workflow EngineAI29/9/202630/9/2026
A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of…
Pendiente de análisisMedia (6.1)0.19%—Wikimedia Mediawiki Flow ExtensionAI29/9/202630/9/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Flow Extension allows Stored XSS. This issue affects Mediawiki - Flow Extension: from * before 1.46.1, 1.45.5, 1.43.10.
En análisisMedia (6.3)0.39%—Apache Airflow Teradata ProviderAI29/9/202629/9/2026
The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the…
En análisisMedia (6.3)0.22%—Apache Airflow Providers SnowflakeAI29/9/202629/9/2026
Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to…