Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (6.3) | 0.22% | — | Apache Airflow Providers SnowflakeAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Snowflake provider did not validate the connection's `account` and `region` fields before interpolating them into request URLs. The SQL API endpoint is built as `https://{account}.snowflakecomputing.com/api/v2/statements`, so an `account` value containing `/`, `?` or `#` demotes the intended domain to… | |
| En análisis | Media (4.3) | 0.29% | — | Apache Airflow Providers GoogleAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the… | |
| En análisis | Media (6.5) | 0.28% | — | Apache Airflow Providers TeradataAI | 29/9/2026 | 29/9/2026 | Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private… | |
| Aplazada | Alta (7.1) | 0.29% | — | Flowring AgentflowAI | 29/9/2026 | 30/9/2026 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
| Aplazada | Alta (8.7) | 0.23% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | |
| Pendiente de análisis | Baja (2.1) | 0.20% | — | LangflowAI | 28/9/2026 | 30/9/2026 | Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into component input options lists. The eval() sink is triggered when a component is… | |
| Aplazada | Alta (7.7) | 0.27% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validation. getAllUpsertHistory() returns UpsertHistory rows selected solely by an attacker-supplied chatflowid, and… | |
| Aplazada | Alta (7.6) | 0.23% | — | Flowiseai FlowiseAIFlowise ComponentsAI | 26/9/2026 | 30/9/2026 | Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no workspaceId condition) in several code paths: getAllOpenaiAssistants/getSingleOpenaiAssistant (GET /api/v1/openai-assistants… | |
| Aplazada | Alta (8.7) | 0.27% | — | Flowiseai FlowiseAI | 26/9/2026 | 5/10/2026 | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASHBOARD=true, and !isCloud()), the /admin/queues mount is protected only by the verifyTokenForBullMQDashboard middleware,… | |
| Aplazada | Crítica (9.2) | 0.29% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming their email at any configured SSO provider. Attackers can gain complete account access including chatflows,… | |
| Aplazada | Crítica (9.2) | 0.37% | — | Flowiseai FlowiseAI | 26/9/2026 | 28/9/2026 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login path. When an SSO callback arrives with an email matching a user whose status is INVITED, verifyAndLogin (SSOBase.ts:80-94) copies the user record from the database — including the server-stored… | |
| Aplazada | Alta (7.5) | 0.22% | — | Flowiseai FlowiseAI | 26/9/2026 | 30/9/2026 | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API keys to read and delete chat history. Attackers with valid but low-privileged API keys can access GET and DELETE chat message routes without required flow permissions to read chat histories, prompts,… | |
| Aplazada | Alta (8.8) | 0.31% | — | Mediaflow ProxyAI | 25/9/2026 | 5/10/2026 | MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs including loopback and cloud metadata endpoints to read full responses from the… | |
| Aplazada | Alta (8) | 0.25% | — | ItflowAI | 25/9/2026 | 30/9/2026 | ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders. | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Apache Airflow Hashicorp ProviderAI | 24/9/2026 | 25/9/2026 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different… | |
| Aplazada | Alta (8.8) | 0.42% | — | Lfprojects MlflowAI | 23/9/2026 | 24/9/2026 | MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact. | |
| Aplazada | Alta (8.8) | 0.39% | — | Lfprojects MlflowAI | 23/9/2026 | 23/9/2026 | MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact. | |
| Pendiente de análisis | Alta (7.6) | 1.5% | — | Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Aplazada | Media (4.1) | 0.12% | — | Nt-ware Uniflow OnlineAI | 23/9/2026 | 23/9/2026 | A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the… | |
| Analizada | Crítica (9.1) | 0.75% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An… | |
| Analizada | Media (4.2) | 0.73% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the… | |
| Analizada | Media (4.3) | 0.64% | — | Apache Airflow | 21/9/2026 | 25/9/2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event… |