Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

2803 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.50%—Oasdiff-actionAI31/8/20269/9/2026
oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the OpenAPI spec by default (allow-external-refs: true). When an action runs on a pull request whose spec is…
AplazadaMedia (5.5)0.47%—Inbox Foundry Activeinbox ExtensionAI31/8/202631/8/2026
A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The…
AplazadaCrítica (9.3)0.51%—Hulumi PoliciesAIGithub ActionsAI31/8/20262/9/2026
@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails.
AplazadaMedia (6.8)0.23%—Leyan Medical Practice Management SystemAI28/8/202628/8/2026
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote attackers can obtain sensitive information via victim's browser history or log files.
Pendiente de análisisMedia (5.5)0.15%—Activecampaign GeneralAI26/8/202628/8/2026
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied…
AplazadaCrítica (9.8)0.88%—AntflowAIActivitiAI26/8/20263/9/2026
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
AplazadaAlta (8.6)0.64%—Leyan Medical Practice Management SystemAI25/8/202626/8/2026
Medical Practice Management System developed by Le-yan has a Remote Code Execution vulnerability. Unauthenticated remote attackers can execute arbitrary OS commamnds via a crafted HTML page.
AplazadaAlta (8.7)0.35%—Actions Upload-artifactAIActions Download-artifactAI24/8/202624/9/2026
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and…
AplazadaMedia (5.5)0.58%—Ractivejs RactiveAI24/8/202626/8/2026
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit has been made available to the…
Pendiente de análisisMedia (4.3)0.19%—MS Graph FOR Active Directory APP FOR Splunk SoarAI19/8/202620/8/2026
In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface.…
AplazadaMedia (6.5)0.56%—Actix-webAIJoin-lemmy LemmyAI19/8/20269/9/2026
Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the first value of X-Forwarded-For as the client address used by raw_ip_key in crates/utils/src/rate_limit/mod.rs. Lemmy's bundled docker/nginx.conf uses…
Pendiente de análisisMedia (6.3)0.57%—Actix-httpAI14/8/202624/9/2026
actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Length and Transfer-Encoding: chunked headers. Unauthenticated remote attackers can exploit this through a front-end intermediary to desynchronize backend requests and…
Pendiente de análisisMedia (6.3)0.47%—Actix FilesAI14/8/202624/9/2026
The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the service then joins the request path with this empty path and canonicalizes it, causing…
Pendiente de análisisMedia (6.9)0.49%—Actix-filesAI14/8/202624/9/2026
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
AplazadaMedia (6.5)0.41%—Github ActionsAI13/8/202626/8/2026
The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creates a new runner registration token if none exists, yet the API scope middleware classifies it as read-only because it is a GET request. A holder of a leaked read:user-scoped token can therefore mint…
AplazadaCrítica (9.3)0.40%—Active Products TablesAI13/8/202614/8/2026
Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
AplazadaAlta (8.8)0.46%—Booking ActivitiesAI13/8/202614/8/2026
Unauthenticated PHP Object Injection in Booking Activities <= 1.18.4 versions.
Pendiente de análisisAlta (8.8)0.68%—Cloudflare Pages-actionAICloudflare Wrangler-actionAI12/8/202628/8/2026
Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose workflow secrets such as CLOUDFLARE_API_TOKEN…
AplazadaMedia (6.1)0.36%—ActivepiecesAI11/8/20269/9/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can break out of the…
AplazadaAlta (7.6)0.25%—ActivepiecesAI11/8/20269/9/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js require(), before the V8 isolate is applied. Top-level module code can therefore call require('child_process'), access fs,…
AplazadaMedia (5.3)0.43%—ActivepiecesAI11/8/20269/9/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the…
AplazadaAlta (8.7)0.53%—ActivepiecesAI11/8/20269/9/2026
Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that path to a shell-invoked build command. A step name containing shell metacharacters can break out of the intended build…
Pendiente de análisisMedia (5.6)0.12%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI11/8/202612/8/2026
Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may…
Pendiente de análisisAlta (8.2)0.32%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI11/8/202612/8/2026
Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AnalizadaCrítica (9.9)0.82%—Microsoft Azure Active Directory7/8/20267/8/2026
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Orbitaley — Vulnerabilidades