Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
982 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.9) | 0.55% | — | Argoproj Argo Workflows | 16/7/2026 | 30/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of… | |
| Aplazada | Baja (1.9) | 0.17% | — | Makafeli N8n-workflow-builderAI | 13/7/2026 | 15/7/2026 | A vulnerability was identified in makafeli n8n-workflow-builder up to 0.11.0. Affected is an unknown function of the file build/server.cjs of the component update_node_from_file. The manipulation of the argument filePath leads to path traversal. An attack has to be approached locally. The exploit is publicly available… | |
| Aplazada | Media (5.3) | 0.56% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 14/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft… | |
| Aplazada | Media (5.3) | 0.52% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 15/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's… | |
| Analizada | Crítica (9.8) | 2.1% | — | Localgovdrupal Localgov Workflows | 10/7/2026 | 6/8/2026 | Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0. | |
| Analizada | Media (6.1) | 0.25% | — | IBM Engineering Workflow Management | 22/6/2026 | 1/10/2026 | IBM Engineering Workflow Management 7.0.2 through 7.0.2 Interim Fix 035, 7.0.3 through 7.0.3 Interim Fix 017, and 7.1 through 7.1 Interim Fix 004 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the… | |
| Analizada | Media (5.4) | 0.23% | — | IBM Engineering Workflow Management | 22/6/2026 | 30/9/2026 | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to… | |
| Aplazada | Baja (2.2) | 0.09% | — | Github WorkflowsAI | 17/6/2026 | 22/6/2026 | The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location. | |
| Analizada | Media (4.3) | 0.22% | — | IBM Business Automation Workflow | 27/5/2026 | 17/6/2026 | IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages. | |
| Aplazada | Media (6.4) | 0.28% | — | Aiwu AI Chatbot Workflow AutomationAI | 20/5/2026 | 24/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.5) | 0.40% | — | Eight DAY Week Print WorkflowAI | 12/5/2026 | 17/6/2026 | The Eight Day Week Print Workflow plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'title' parameter in the `pp-get-articles` AJAX action in all versions up to, and including, 1.2.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Alta (7.5) | 0.69% | — | Aiwu AI Chatbot Workflow AutomationAI | 12/5/2026 | 17/6/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This makes it possible for… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Modificada | Alta (8.5) | 0.53% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zero authorization checks on all CRUD operations (create, read, update, delete).… | |
| Modificada | Alta (8.1) | 0.49% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add… | |
| Analizada | Alta (8.5) | 0.40% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor logs all artifact repository credentials (S3 access keys, secret keys, GCS service account keys, Azure account keys, Git passwords, etc.) in… | |
| Modificada | Alta (8.2) | 0.74% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads the entire request body into memory before authenticating the request or verifying its signature. This occurs on the /api/v1/events/… | |
| Analizada | Baja (2.3) | 0.57% | — | Argoproj Argo Workflows | 9/5/2026 | 24/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes a panic (denial of service) for SSO users whose claims match a namespace-level… | |
| Modificada | Alta (7.7) | 0.59% | — | Argoproj Argo Workflows | 23/4/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy… | |
| Analizada | Media (5.5) | 0.33% | — | Oracle Workflow | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in… | |
| Aplazada | Media (5.5) | 0.50% | — | Nocobase Plugin-workflow-javascriptAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The… | |
| Aplazada | Media (5.3) | 0.29% | — | Massiveshift AI Workflow Automation LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in massiveshift AI Workflow Automation ai-workflow-automation-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Workflow Automation: from n/a through <= 1.4.2. | |
| Analizada | Media (6.1) | 0.37% | — | Workflowfirst Staffwiki | 26/3/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted HTTP request. | |
| Modificada | Alta (8.9) | 0.65% | — | Argoproj Argo Workflows | 11/3/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow… | |
| Modificada | Alta (7.5) | 0.78% | — | Argoproj Argo Workflows | 11/3/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 4.0.2 and 3.7.11, Workflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a Authorization: Bearer nothing token can leak… |