Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | — | |
| Aplazada | Alta (8.1) | 0.49% | 💥 PoC | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting… | |
| Aplazada | Alta (8.8) | 0.52% | 💥 PoC | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 15/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive… | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. | |
| Aplazada | Crítica (9.3) | 0.36% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Crítica (9) | 0.27% | — | Sage AR Automation APIAICash CollectAI | 9/9/2026 | 9/9/2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges. | |
| Aplazada | Crítica (9) | 0.27% | — | Sage AR Automation APIAI | 9/9/2026 | 9/9/2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier. | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Next4biz Information Technologies INC CSMAI | 7/9/2026 | 9/9/2026 | Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3. | |
| Aplazada | Alta (7.5) | 0.50% | — | Next4biz Information Technologies INC CSMAI | 7/9/2026 | 8/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Path Traversal. This issue affects CSM (Customer Service Management): from 6.8.9 before 8.0.3. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Information System Society Membership SystemAI | 7/9/2026 | 28/9/2026 | A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… |