Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
14.251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Email Subscribers AND NewslettersAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | |
| Aplazada | Media (6.9) | 0.41% | — | Extendthemes Kubio AI Website BuilderAI | 31/8/2026 | 8/9/2026 | Improper input validation vulnerability in Extend Themes Kubio AI Website Builder. This issue affects Kubio AI Website Builder: before 2.9.1. | |
| Aplazada | Alta (8.7) | 0.52% | — | Androidbubbles Keep Backup DailyAI | 31/8/2026 | 8/9/2026 | Keep Backup Daily plugin for WordPress before 2.1.4 contains a sensitive information exposure vulnerability that allows unauthenticated attackers to trigger a full MySQL database dump by accessing the publicly exposed `kbd_cron_process` parameter without authentication. Attackers can predict the partially predictable… | |
| Aplazada | Alta (7.8) | 0.49% | — | Tubitak Bilgem Pardus Boot RepairAI | 31/8/2026 | 1/9/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8. | |
| Aplazada | Media (5.1) | 0.31% | — | Aix-dbAI | 31/8/2026 | 8/9/2026 | Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers… | |
| Pendiente de análisis | Crítica (9.3) | 2.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without… | |
| Pendiente de análisis | Media (6.9) | 1.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for… | |
| Pendiente de análisis | Alta (8.3) | 0.19% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls. | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny… | |
| Aplazada | Media (5.3) | 0.30% | — | AicaijiAI | 31/8/2026 | 31/8/2026 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them, allowing unauthenticated users to create WordPress user accounts and taxonomy terms. | |
| Aplazada | Baja (2.1) | 0.41% | — | KamailioAI | 31/8/2026 | 31/8/2026 | A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly… | |
| Aplazada | Media (5.3) | 0.47% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is… | |
| Aplazada | Media (6) | 0.47% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through… | |
| Aplazada | Alta (7.1) | 0.54% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool… | |
| Aplazada | Alta (7.1) | 0.47% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw… | |
| Aplazada | Alta (7.4) | 0.28% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins: nil, origin_allowed?/3 accepts an origin… | |
| Aplazada | Alta (8.9) | 0.28% | — | Ash-project ASH AIAI | 31/8/2026 | 1/9/2026 | Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content… | |
| Aplazada | Alta (8.7) | 0.50% | — | Jina AI ReaderAI | 30/8/2026 | 1/9/2026 | jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content. | |
| Aplazada | Media (5.9) | 0.12% | — | Ash-project ASH Paper TrailAI | 30/8/2026 | 1/9/2026 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore only act on the tracked resource's… | |
| Aplazada | Baja (2.1) | 0.18% | — | Ash-project ASH Paper TrailAI | 30/8/2026 | 1/9/2026 | Inefficient Algorithmic Complexity vulnerability in ash-project ash_paper_trail allows a user who can submit a large array attribute to a paper-trailed create or update action to cause a denial of service through excessive CPU and memory use. With full-diff change tracking,… | |
| Aplazada | Media (5.9) | 0.12% | — | Ash-project ASH Paper TrailAI | 30/8/2026 | 1/9/2026 | Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover the plaintext of sensitive? attributes. AshPaperTrail stores the values of tracked sensitive? attributes in the generated version resource's changes… | |
| Aplazada | Crítica (9.3) | 0.35% | — | AicaijiAI | 29/8/2026 | 31/8/2026 | The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue… |