Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
14.265 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.24% | — | Lime Technology INC Unraid OSAI | 26/8/2026 | 9/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication cookie's lax same-site policy. | |
| Aplazada | Crítica (9.8) | 1.2% | — | Senaite CoreAI | 26/8/2026 | 9/9/2026 | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in… | |
| Aplazada | Alta (8.5) | 0.39% | — | Stalwart Mail ServerAI | 26/8/2026 | 24/9/2026 | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the… | |
| Aplazada | Alta (7.1) | 0.48% | — | Mage AIAI | 26/8/2026 | 24/9/2026 | Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in mage_ai/api/resources/BrowserItemResource.py passes a caller-supplied path to the filesystem read and write helpers without calling the containment helper that the sibling FileContentResource and… | |
| Aplazada | Crítica (9.8) | 0.55% | — | UI Unifi Protect AI KEYAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. | |
| Aplazada | Media (5.3) | 0.30% | — | AI EngineAI | 26/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only features, relying instead on a token it hands out to anonymous visitors, allowing unauthenticated attackers to run AI queries of their own choosing against the site owner's configured provider account. | |
| Aplazada | Alta (7.7) | 0.44% | — | AI EngineAI | 26/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host.… | |
| Aplazada | Alta (8.7) | 0.36% | — | KimaiAI | 26/8/2026 | 3/9/2026 | Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other user) with permission to edit a team can… | |
| Aplazada | Alta (8.7) | 0.31% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no authorization checks. Any authenticated user,… | |
| Aplazada | Alta (8.7) | 0.47% | — | KimaiAI | 26/8/2026 | 31/8/2026 | Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization… | |
| Aplazada | Crítica (9.3) | 0.45% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently… | |
| Aplazada | Baja (2) | 0.26% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API tokens in rendered invoice output. | |
| Aplazada | Media (5.3) | 0.36% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for… | |
| Aplazada | Media (6.3) | 0.31% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users, enabling username enumeration with no login… | |
| Aplazada | Alta (8.7) | 0.43% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML… | |
| Aplazada | Alta (8.7) | 0.26% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by referencing their timesheet identifier,… | |
| Aplazada | Alta (8.7) | 0.53% | — | KimaiAI | 26/8/2026 | 8/10/2026 | Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour… | |
| Pendiente de análisis | Media (5.7) | 0.19% | — | Drupal Email Login OTPAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | |
| Aplazada | Alta (7.2) | 0.43% | — | ChainlitAI | 25/8/2026 | 9/9/2026 | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http transports,… | |
| Aplazada | Crítica (9.8) | 1.1% | — | ChainlitAI | 25/8/2026 | 9/9/2026 | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a… | |
| Analizada | Crítica (10) | 3.5% | — | Adobe Campaign | 25/8/2026 | 1/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation… | |
| Analizada | Crítica (10) | 3.5% | — | Adobe Campaign | 25/8/2026 | 2/9/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation… | |
| Analizada | Crítica (10) | 1.3% | — | Adobe Campaign | 25/8/2026 | 1/9/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is… | |
| Analizada | Alta (7.8) | 0.26% | — | Adobe Substance 3D Painter | 25/8/2026 | 31/8/2026 | Substance3D - Painter is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Analizada | Alta (7.8) | 0.34% | — | Adobe Substance 3D Painter | 25/8/2026 | 31/8/2026 | Substance3D - Painter is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. |