Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

14.241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.35%—TaskingaiAI2/10/20266/10/2026
In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter.
Pendiente de análisisCrítica (9.8)0.33%—Sinaptik AI Pandas-aiAI2/10/20266/10/2026
sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
Pendiente de análisisCrítica (9.9)0.94%💥 PoCGitlab AI GatewayAI2/10/20262/10/2026
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template…
AplazadaMedia (4.7)0.17%—Mehul Gohil Aculect AI CompanionAI2/10/20262/10/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1.
AplazadaMedia (6.5)0.19%—Kiera Howe WebsamuraiAI2/10/20262/10/2026
Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7.
AplazadaMedia (6.5)0.17%—Airano MCP BridgeAI2/10/20263/10/2026
Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/a through 2.11.0.
AplazadaMedia (6.1)0.21%—Aioseo ALL IN ONE SEOAI2/10/20263/10/2026
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it…
AplazadaAlta (7.4)0.16%—Havelsan SEF AI Chatbot PlatformAI2/10/20262/10/2026
Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
AplazadaAlta (7.2)0.31%—Kubio AI Page BuilderAI2/10/20263/10/2026
The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AplazadaMedia (4.3)0.22%—Awesomemotive WP Mail LoggingAI2/10/20262/10/2026
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log…
AplazadaMedia (5.3)0.25%—CMP Coming Soon MaintenanceAI2/10/20262/10/2026
The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request…
AplazadaCrítica (9.8)0.51%—Langchain ChatchatAI1/10/20265/10/2026
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.
AplazadaCrítica (9.1)0.35%—Chatchat-space Langchain-chatchatAI1/10/20265/10/2026
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge…
AplazadaSin puntuar0.14%—Chatchat-space Langchain-chatchatAI1/10/20262/10/2026
The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.
AplazadaCrítica (9.1)0.35%—Stitionai DevikaAI1/10/20265/10/2026
In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially compromising the entire server.
AplazadaAlta (7.5)0.33%—Stitionai DevikaAI1/10/20265/10/2026
In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.
AplazadaAlta (8.8)0.26%—Stitionai DevikaAI1/10/20266/10/2026
Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.
AplazadaAlta (8.7)0.26%—Sakailms SakaiAI1/10/20266/10/2026
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site…
AnalizadaCrítica (9.8)2.2%⚠ Explotación activa💥 PoCFortinet Fortimail1/10/20262/10/2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system…
AplazadaMedia (6.9)0.13%—Joyland AIAI1/10/20261/10/2026
The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
AplazadaMedia (5.3)0.11%—Joyland AIAI1/10/20261/10/2026
Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
AplazadaMedia (6.9)0.18%—Joyland AIAI1/10/20261/10/2026
Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
AplazadaMedia (6.9)0.12%—Joyland AIAI1/10/20261/10/2026
The Joyland AI app accepts any TLS certificates from any server without validation.
AplazadaCrítica (9)0.19%—Joyland AIAI1/10/20262/10/2026
Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream' module, or access app-internal storage. If the installed app has been granted…
AplazadaMedia (6.9)0.17%—Joyland AIAI1/10/20261/10/2026
The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all users of the app at once.