Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
401.466 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.3) | 0.26% | — | UtmstackAI | 2/10/2026 | 5/10/2026 | UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this… | |
| Recibida | Media (6.9) | 0.25% | — | UtmstackAI | 2/10/2026 | 2/10/2026 | UTMStack before 11.2.16 contains an account enumeration vulnerability that allows unauthenticated attackers to determine registered email addresses by observing differing HTTP responses from the POST /api/account/reset-password/init endpoint. Attackers can submit arbitrary email addresses and distinguish registered… | |
| Recibida | Crítica (9.3) | 0.55% | — | UtmstackAI | 2/10/2026 | 5/10/2026 | UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path… | |
| Recibida | Media (6.5) | 0.44% | — | UtmstackAI | 2/10/2026 | 5/10/2026 | UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role,… | |
| Recibida | Crítica (9.4) | 0.53% | — | — | 2/10/2026 | 3/10/2026 | A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device. | |
| Recibida | Media (5.3) | 0.30% | — | MultidictAI | 2/10/2026 | 5/10/2026 | Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value… | |
| Recibida | Media (5.3) | 0.29% | — | Canonical Postgresql OperatorAI | 2/10/2026 | 3/10/2026 | The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated "monitoring" PostgreSQL user. On database connection errors, the exporter writes the monitoring user's password in cleartext to its logs. Any actor able to read those logs can recover the password, which… | |
| Recibida | Media (5.3) | 0.19% | — | UtmstackAI | 2/10/2026 | 5/10/2026 | UTMStack before 11.2.16 contains a server-side request forgery vulnerability in IdentityProviderService.validateMetadataUrl() that allows authenticated attackers to make the server send requests to arbitrary internal or cloud metadata hosts by supplying a malicious metadata URL to the identity-providers endpoint.… | |
| Recibida | Alta (8.7) | 0.34% | — | UtmstackAI | 2/10/2026 | 5/10/2026 | UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can… | |
| Recibida | Alta (8.8) | 0.14% | — | Webriti WallstreetAI | 2/10/2026 | 2/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Webriti Wallstreet wallstreet allows Cross Site Request Forgery.This issue affects Wallstreet: from n/a through 2.8.6. | |
| Recibida | Media (5.3) | 0.27% | — | Canonical MaasAI | 2/10/2026 | 4/10/2026 | An information exposure vulnerability in Canonical MAAS prior to versions 3.4.10, 3.5.14, 3.6.5, 3.7.3, and 3.8.0 allows an unauthenticated attacker to retrieve the RPC secret in plaintext via the vendor data metadata endpoint. If a target machine was deployed with the 'register as rack' option enabled, an attacker… | |
| Aplazada | Baja (2.5) | 0.20% | — | Aquasec TrivyAI | 2/10/2026 | 5/10/2026 | Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those… | |
| Recibida | Alta (7.1) | 0.22% | — | PhprojectAI | 2/10/2026 | 2/10/2026 | Phproject before 1.8.7 contains a missing object-level authorization vulnerability in the REST API issue endpoints (single_get, single_comments, single_comments_post) that allows authenticated API key holders to bypass the security.restrict_access confidentiality control by never invoking the allowAccess()… | |
| Recibida | Alta (8.1) | 0.20% | — | Dogtagpki Pki-coreAI | 2/10/2026 | 5/10/2026 | A flaw was found in Dogtag PKI (pki-core). The CMCAuthForEST authentication plugin fails open when an EST fullcmc enrollment request is submitted via BasicAuth without an end-user TLS client certificate. The SSL_CLIENT_CERT session attribute retains the EST subsystem's agent certificate, which causes downstream… | |
| Recibida | Alta (7.6) | 0.25% | — | Langchain Langgraph SDKAI | 2/10/2026 | 5/10/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and… | |
| Recibida | Media (5.8) | 0.24% | — | Opentelemetry Instrumentation Cassandra DriverAIOpentelemetry Instrumentation KnexAIOpentelemetry Instrumentation MongooseAIOpentelemetry Instrumentation MysqlAI+4 | 2/10/2026 | 2/10/2026 | OpenTelemetry JavaScript Contrib provides instrumentation libraries for collecting telemetry from JavaScript applications. Prior to versions 0.66.0 of @opentelemetry/instrumentation-cassandra-driver, 0.65.0 of @opentelemetry/instrumentation-knex, 0.67.0 of @opentelemetry/instrumentation-mongoose,… | |
| Recibida | Media (6.3) | 0.42% | — | Angular SSRAI | 2/10/2026 | 2/10/2026 | The Angular SSR is a server-rise rendering tool for Angular applications. Prior to versions 20.3.36, 21.2.23, and 22.1.7, the CommonEngine retrieveSSGPage prerendered-page retrieval logic in @angular/ssr/node, and in @angular/ssr for versions 17 through 18, accepts a relative request URL containing a backslash… | |
| Recibida | Crítica (9.3) | 1.4% | — | Amazon Sagemaker DistributionAI | 2/10/2026 | 2/10/2026 | OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated… | |
| Recibida | Media (6.5) | 0.23% | — | Orpc ZODAI | 2/10/2026 | 5/10/2026 | oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.10, the @orpc/zod ZodSmartCoercionPlugin and experimental_ZodSmartCoercionPlugin collect object and record properties in plain objects and resolve shape keys through the prototype chain. A remote client… | |
| Recibida | Media (6.5) | 0.23% | — | Orpc Json-schemaAI | 2/10/2026 | 5/10/2026 | oRPC is a tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to 1.14.9, the @orpc/json-schema SmartCoercionPlugin uses JsonSchemaCoercer to collect object properties in a plain object and to resolve schema.properties entries through the prototype chain. A remote client that… | |
| Recibida | Alta (8.8) | 0.50% | — | Microsoft Exchange ServerAI | 2/10/2026 | 3/10/2026 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. | |
| Recibida | Media (6.5) | 0.18% | — | Aioseo ALL IN ONE SEOAI | 2/10/2026 | 2/10/2026 | The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the… | |
| Recibida | Alta (8.3) | 0.33% | — | Loom FOR AWSAI | 2/10/2026 | 2/10/2026 | Server-side request forgery in the tool server and remote agent connection handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the credentials of the application's own container role and to read responses from arbitrary internal network locations, via a crafted connection address… | |
| Recibida | Alta (8.2) | 0.38% | — | Loom FOR AWSAI | 2/10/2026 | 2/10/2026 | Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document… | |
| Recibida | Crítica (10) | 0.47% | — | Loom FOR AWSAI | 2/10/2026 | 2/10/2026 | Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to… |