Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | LangflowAI | 20/4/2026 | 17/6/2026 | A security flaw has been discovered in langflow-ai langflow up to 1.1.0. This issue affects the function create_upload_file of the file src/backend/base/Langflow/api/v1/endpoints.py of the component API Endpoint. The manipulation results in unrestricted upload. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.4) | 0.36% | — | Apache-airflow-providers-keycloak | 18/4/2026 | 17/6/2026 | The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state` parameter on the login / login-callback flow, and did not use PKCE. An attacker with a Keycloak account in the same realm could deliver a crafted callback URL to a victim's browser and cause… | |
| Analizada | Baja (3.7) | 0.66% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked. If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0… | |
| Analizada | Alta (7.5) | 0.72% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate to Airflow version 3.2.0 that fixes the issue. | |
| Analizada | Alta (7.5) | 0.76% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Analizada | Alta (8.8) | 1.0% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advice. | |
| Modificada | Alta (7.2) | 1.1% | — | Apache Airflow | 18/4/2026 | 17/6/2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue. | |
| Analizada | Alta (7.1) | 0.55% | — | Bytedance Deerflow | 17/4/2026 | 14/7/2026 | ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-mode custom-agent creation where the agent name validation is bypassed. Attackers can supply traversal-style values or absolute paths as the agent name to influence directory creation and write files… | |
| Analizada | Alta (7.5) | 0.83% | — | Apache Airflow | 16/4/2026 | 17/6/2026 | JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue. | |
| Analizada | Media (6.5) | 0.55% | — | Apache Airflow | 15/4/2026 | 17/6/2026 | The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Azure Service Bus used… | |
| Analizada | Alta (8.1) | 0.58% | — | Apache Airflow | 15/4/2026 | 7/10/2026 | El ejemplo example_xcom que se incluyó en la documentación de Airflow implementó un patrón inseguro de lectura de valores de xcom de una manera que podría ser explotada para permitir que un usuario de la interfaz de usuario (UI) que tuviera acceso para modificar XComs realizara la ejecución arbitraria de código en el… | |
| Aplazada | Media (5.5) | 0.50% | — | Nocobase Plugin-workflow-javascriptAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/plugin-workflow-javascript/src/server/Vm.js. Performing a manipulation results in sandbox issue. The attack can be initiated remotely. The… | |
| Analizada | Alta (8.8) | 1.1% | — | Apache Airflow | 13/4/2026 | 17/6/2026 | Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended to upgrade to Apache Airflow 3.2.0, which resolves this… | |
| Analizada | Alta (7.5) | 0.44% | — | Apache Airflow | 13/4/2026 | 7/10/2026 | Antes de Airflow 3.2.0, no estaba claro que las implementaciones seguras de Airflow requieren que el Gestor de Implementación tome las acciones apropiadas y preste atención a los detalles de seguridad y al modelo de seguridad de Airflow. Algunas suposiciones que el Gestor de Implementación podría hacer no eran lo… | |
| Aplazada | Baja (2.1) | 0.39% | — | Dromara Warm-flowAI | 12/4/2026 | 17/6/2026 | A security flaw has been discovered in Dromara warm-flow up to 1.8.4. Impacted is the function SpelHelper.parseExpression of the file /warm-flow/save-json of the component Workflow Definition Handler. The manipulation of the argument listenerPath/skipCondition/permissionFlag results in code injection. The attack may… | |
| Analizada | Media (6.5) | 0.79% | — | Apache Airflow | 9/4/2026 | 17/6/2026 | Apache Airflow versions 3.0.0 through 3.1.8 DagRun wait endpoint returns XCom result values even to users who only have DAG Run read permissions, such as the Viewer role.This behavior conflicts with the FAB RBAC model, which treats XCom as a separate protected resource, and with the security model documentation that… | |
| Analizada | Crítica (9.1) | 0.67% | — | Apache Airflow | 9/4/2026 | 7/10/2026 | Cuando el usuario cerró sesión, el token JWT con el que se había autenticado no fue invalidado, lo que podría llevar a la reutilización de ese token en caso de que fuera interceptado. En Airflow 3.2 implementamos el mecanismo que implementa la invalidación de tokens al cerrar sesión. Los usuarios que estén preocupados… | |
| Aplazada | Media (5.3) | 1.8% | — | Agions Taskflow-aiAI | 9/4/2026 | 24/7/2026 | Una falla de seguridad ha sido descubierta en Agions taskflow-ai hasta la versión 2.1.8. Esto afecta una función desconocida del archivo src/mcp/server/handlers.ts del componente terminal_execute. Realizar una manipulación resulta en inyección de comandos del sistema operativo. El ataque puede ser llevado a cabo de… | |
| Aplazada | Media (5.3) | 0.29% | — | Massiveshift AI Workflow Automation LiteAI | 8/4/2026 | 24/7/2026 | Vulnerabilidad de autorización faltante en massiveshift AI Workflow Automation ai-workflow-automation-lite permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a AI Workflow Automation: desde n/a hasta <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.23% | — | Brainstormforce CartflowsAI | 8/4/2026 | 20/7/2026 | Vulnerabilidad por ausencia de autorización en Brainstorm Force CartFlows cartflows permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a CartFlows: desde n/a hasta <= 2.2.3. | |
| Analizada | Alta (8.8) | 0.65% | — | Langflow | 8/4/2026 | 24/7/2026 | IBM Langflow Desktop 1.6.0 hasta 1.8.2 Langflow podría permitir a un usuario autenticado ejecutar código arbitrario en el sistema, causado por una configuración predeterminada insegura que permite la deserialización de datos no confiables en el componente FAISS. | |
| Analizada | Alta (8.7) | 2.6% | 💥 Exploit | Nextcloud FlowWindmill | 7/4/2026 | 17/6/2026 | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not… | |
| Analizada | Media (5.3) | 0.37% | — | Lfprojects Mlflow | 7/4/2026 | 17/6/2026 | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. This issue… | |
| Analizada | Media (5.1) | 0.30% | — | Lfprojects Mlflow | 7/4/2026 | 17/6/2026 | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows actions such as session… | |
| Analizada | Alta (8.7) | 0.56% | 💥 PoC | Infiniflow Ragflow | 3/4/2026 | 24/7/2026 | RAGFlow es un motor RAG (Generación Aumentada por Recuperación) de código abierto. En las versiones 0.24.0 y anteriores, existe una vulnerabilidad de Inyección de Plantillas del Lado del Servidor (SSTI) en los componentes de Procesamiento de Texto (StringTransform) y Mensaje del flujo de trabajo del Agente de RAGFlow.… |