Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
14.244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.50% | — | Jetbrains HUBAI | 7/9/2026 | 9/9/2026 | In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges | |
| Aplazada | Alta (8.1) | 0.35% | — | Jetbrains YoutrackAI | 7/9/2026 | 9/9/2026 | In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR | |
| Aplazada | Crítica (9.8) | 0.61% | — | Jetbrains YoutrackAI | 7/9/2026 | 9/9/2026 | In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address | |
| Aplazada | Alta (8.8) | 0.42% | — | Jetbrains YoutrackAI | 7/9/2026 | 22/9/2026 | In JetBrains YouTrack before 2026.2.18634, insufficient validation of role assignments allowed privilege escalation | |
| Aplazada | Media (6.5) | 0.33% | — | Blog Studio Email Subscribers AND NewslettersAI | 7/9/2026 | 8/9/2026 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly… | |
| Aplazada | Media (6.8) | 0.16% | — | Eclipse AnkaiosAI | 7/9/2026 | 8/9/2026 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf message received through the Control Interface FIFO. A workload granted Control Interface access can specify an excessive message length, causing an unbounded memory allocation… | |
| Aplazada | Alta (8.3) | 0.16% | — | Eclipse AnkaiosAI | 7/9/2026 | 8/9/2026 | In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a CompleteStateRequest or UpdateStateRequest with an empty… | |
| Pendiente de análisis | Media (6.5) | 0.35% | — | Redhat Openshift AIAIRedhat Odh-dashboardAI | 7/9/2026 | 8/9/2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the… | |
| Aplazada | Media (5.5) | 0.53% | — | Baidu UeditorAIFeehicmsAI | 7/9/2026 | 28/9/2026 | A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit is… | |
| Aplazada | Crítica (9) | 0.42% | 💥 PoC | OpenmaicAI | 6/9/2026 | 10/9/2026 | OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via the x-base-url header or baseUrl parameter to access sensitive cloud credentials and metadata. | |
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Daily Expense ManagerAI | 6/9/2026 | 8/9/2026 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Crítica (9.8) | 0.66% | 💥 PoC | Mail MintAI | 5/9/2026 | 8/9/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated… | |
| Aplazada | Alta (7.2) | 0.29% | — | Brainstormforce SureformsAI | 5/9/2026 | 8/9/2026 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Pendiente de análisis | Alta (8.9) | 0.51% | 💥 PoC | LaravelAISymfony MailerAISymfony MimeAI | 4/9/2026 | 10/9/2026 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in… | |
| Aplazada | Alta (8.5) | 0.25% | — | Aider-chatAI | 4/9/2026 | 10/9/2026 | aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell (subprocess with shell=True) without any user… | |
| Aplazada | Crítica (9.3) | 0.70% | — | AIMAI | 4/9/2026 | 10/9/2026 | Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete runs. | |
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… | |
| Aplazada | Media (6.1) | 0.25% | 💥 PoC | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and… | |
| Pendiente de análisis | Alta (7.1) | 0.39% | — | GFI Exinda AIAIGFI ClearviewAI | 4/9/2026 | 10/9/2026 | GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary iperf flags. An authenticated attacker… | |
| Pendiente de análisis | Alta (7) | 0.93% | — | GFI Exinda AIAIGFI ClearviewAI | 4/9/2026 | 8/9/2026 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without sanitizing for directory traversal sequences. An… | |
| Pendiente de análisis | Media (6.9) | 0.84% | — | GFI Exinda AIAIGFI ClearviewAI | 4/9/2026 | 8/9/2026 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration directory path without sanitizing for… | |
| Aplazada | Alta (8.7) | 0.48% | — | Jina AI ReaderAI | 4/9/2026 | 24/9/2026 | jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata endpoints, allowing the server to fetch and… | |
| Aplazada | Crítica (9.8) | 0.83% | — | AI Website BuilderAI | 4/9/2026 | 8/9/2026 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of their choosing into the uploads directory,… | |
| Pendiente de análisis | Crítica (10) | 0.92% | — | Microsoft Azure AI LanguageAI | 3/9/2026 | 8/9/2026 | Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.3) | 0.34% | — | Brainstormforce SureformsAI | 3/9/2026 | 7/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5. |