Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
40.032 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Crítica (9.2) | 0.24% | — | RabbitmqAI | 23/9/2026 | 29/9/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-middle position can forge the JWKS response, which leads the broker to accept… | |
| En análisis | Crítica (9.1) | 0.25% | — | RabbitmqAI | 23/9/2026 | 29/9/2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 →… | |
| Pendiente de análisis | Crítica (9.4) | 0.61% | — | WP ToolkitAICpanelAI | 23/9/2026 | 24/9/2026 | Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts. | |
| Pendiente de análisis | Crítica (9.4) | 0.58% | — | CpanelAI | 23/9/2026 | 24/9/2026 | Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges. | |
| Pendiente de análisis | Crítica (9.4) | 1.0% | — | PleskAI | 23/9/2026 | 24/9/2026 | OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges. | |
| Pendiente de análisis | Crítica (9.9) | 0.43% | — | Ansible Automation PlatformAIAnsible Automation-controllerAI | 23/9/2026 | 25/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that… | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | — | Redhat Ansible Automation PlatformAIRedhat AWXAI | 23/9/2026 | 24/9/2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate… | |
| Aplazada | Crítica (9.3) | 0.25% | — | S2s-proxyAI | 23/9/2026 | 24/9/2026 | All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certificate's private key but does not verify the certificate against the configured CA. An… | |
| Aplazada | Crítica (9.3) | 0.25% | — | WBW Product FilterAI | 23/9/2026 | 23/9/2026 | Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions. | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Aplazada | Crítica (9.9) | 0.57% | — | Openc3 CosmosAI | 23/9/2026 | 29/9/2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later executed by multiple configuration paths below the intended code-execution… | |
| Aplazada | Crítica (9.2) | 0.50% | — | OpenbaoAI | 23/9/2026 | 29/9/2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthenticated attacker able to make repeated recovery mode requests and measure response… | |
| Analizada | Crítica (9.1) | 0.32% | — | Claris Filemaker Server | 23/9/2026 | 5/10/2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Crítica (9.1) | 0.29% | — | Claris Filemaker Server | 23/9/2026 | 5/10/2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Aplazada | Crítica (9.3) | 0.43% | — | OrvalAI | 23/9/2026 | 29/9/2026 | orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called. | |
| Aplazada | Crítica (9.3) | 0.54% | — | Orval CoreAI | 23/9/2026 | 23/9/2026 | orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client… | |
| Aplazada | Crítica (9.3) | 0.57% | — | OrvalAI | 23/9/2026 | 23/9/2026 | orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked. | |
| Aplazada | Crítica (9.2) | 0.48% | — | OrvalAI | 23/9/2026 | 23/9/2026 | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process… | |
| Aplazada | Crítica (9.3) | 0.42% | — | OrvalAIOrval EffectAI | 23/9/2026 | 23/9/2026 | orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the… | |
| Aplazada | Crítica (9.3) | 0.43% | — | OrvalAIOrval HonoAI | 23/9/2026 | 29/9/2026 | orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the… | |
| Analizada | Crítica (9.3) | 0.42% | — | Moquette | 23/9/2026 | 28/9/2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no custom class was configured and fall back to AcceptAllAuthenticator or… | |
| Analizada | Crítica (9.6) | 0.27% | — | Moquette | 23/9/2026 | 25/9/2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then treats the result as an MQTT topic filter. A client that uses + or # in either… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Moodle SocialwallAI | 23/9/2026 | 24/9/2026 | SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests | |
| Analizada | Crítica (9.3) | 0.19% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator… |