Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
21.643 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.56% | — | MinifluxAI | 21/8/2026 | 30/9/2026 | Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes because Go URL parsing treats them as path characters. Browser backslash normalization converts them to forward slashes. An unauthenticated attacker can provide such a… | |
| Pendiente de análisis | Media (6.9) | 0.08% | — | Johnsoncontrols Simplex Incident ManagerAIJohnsoncontrols Autocall Fire AdministratorAI | 21/8/2026 | 3/9/2026 | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05. | |
| Aplazada | Alta (8.8) | 0.61% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnigent/spec/parser.py stores the value verbatim and… | |
| Aplazada | Alta (7.1) | 0.40% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single… | |
| Aplazada | Alta (8.8) | 0.65% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path.… | |
| Aplazada | Crítica (9) | 0.51% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a… | |
| Aplazada | Alta (8.5) | 1.1% | — | UAC Unix Like Artifacts CollectorAI | 21/8/2026 | 24/9/2026 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by… | |
| Aplazada | Alta (8.5) | 1.0% | — | UAC Unix Like Artifacts CollectorAI | 21/8/2026 | 24/9/2026 | UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this… | |
| Aplazada | Crítica (9.4) | 0.09% | 💥 PoC | DJI NEOAIDJI NEO 2AIDJI FlipAIDJI AIR 3AI+12 | 21/8/2026 | 26/8/2026 | DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML messages with the drone over BLE,… | |
| Aplazada | Alta (7.5) | 0.49% | — | MOD Auth OpenidcAI | 21/8/2026 | 18/9/2026 | mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is… | |
| Aplazada | Alta (8.7) | 0.55% | — | Genians Genian NACAIGenians Genian ZtnaAI | 21/8/2026 | 3/9/2026 | Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, and Genians Genian ZTNA V6.0 allows SQL Injection and Authentication Bypass. | |
| Pendiente de análisis | Media (6.7) | 0.20% | 💥 PoC | Canonical ApportAI | 20/8/2026 | 28/8/2026 | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files. | |
| Analizada | Crítica (9.8) | 0.47% | — | Apple Swiftnio SSH | 20/8/2026 | 3/9/2026 | A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1. | |
| Pendiente de análisis | Alta (7.7) | 0.60% | — | Langchain CommunityAI | 20/8/2026 | 24/9/2026 | SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf url entries. The loop over url elements filters cross-domain locations, but the loop over nested sitemap elements passes the child loc straight to… | |
| Aplazada | Media (4.7) | 0.29% | — | Dicebear CoreAIDicebear InitialsAI | 20/8/2026 | 18/9/2026 | DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits fontSize and fontWeight without escaping in… | |
| Aplazada | Alta (8.6) | 1.5% | — | Otrs Community EditionAI | 20/8/2026 | 24/9/2026 | OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options. Administrator-supplied configuration values are… | |
| Analizada | Media (5.3) | 0.37% | — | Apple Swiftnio | 20/8/2026 | 28/8/2026 | An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in swift-nio version 2.101.0. | |
| Pendiente de análisis | Baja (2.8) | 0.11% | — | NIXAI | 20/8/2026 | 18/9/2026 | Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can cause writeFile to follow a substituted… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | Canonical AccountsserviceAI | 20/8/2026 | 28/8/2026 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to… | |
| Aplazada | Alta (8.4) | 0.19% | — | Estonian Information System Authority Digidoc4AI | 20/8/2026 | 1/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from 4.0.0 before 4.11.0. | |
| Aplazada | Alta (7.6) | 0.38% | — | Revmakx Infinitewp ClientAI | 20/8/2026 | 24/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9. | |
| Aplazada | Crítica (9.9) | 0.48% | — | Smart CleaningAI | 20/8/2026 | 20/8/2026 | Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions. | |
| Aplazada | Baja (2.1) | 0.33% | — | Amirsanni Mini-inventory-and-sales-management-systemAI | 20/8/2026 | 20/8/2026 | A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the file application/models/Transaction.php. Performing a manipulation of the argument orderBy/orderFormat results in sql injection. It is possible to initiate the attack… | |
| Pendiente de análisis | Baja (3.1) | 0.29% | — | Tanium Threat ResponseAI | 19/8/2026 | 1/9/2026 | Tanium addressed a compression bomb vulnerability in Threat Response. |