Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
14.243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.7) | 0.21% | — | HCL AionAI | 1/10/2026 | 2/10/2026 | HCL AION is affected by a vulnerability in which the Content-Security-Policy (CSP) HTTP response header is not configured. CSP helps prevent attacks such as Cross-Site Scripting (XSS) by restricting the sources from which scripts, styles, and other resources can be loaded. The absence of this header may reduce the… | |
| Aplazada | Alta (8.6) | 0.34% | — | Acymailing Smtp NewsletterAI | 1/10/2026 | 1/10/2026 | Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions. | |
| Aplazada | Alta (8.8) | 0.23% | — | Bytecore MCP Connector FOR AI ToolsAI | 1/10/2026 | 1/10/2026 | Subscriber Privilege Escalation in ByteCoreStack – MCP Connector for AI Tools <= 1.2.2 versions. | |
| Analizada | Media (5.5) | 0.15% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 sSRF was possible via the GitHub VCS integration | |
| Analizada | Media (5.4) | 0.14% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in inbox threads allowed reading other users' notifications | |
| Analizada | Media (4.3) | 0.19% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed reloading of translation catalogs | |
| Analizada | Media (6.6) | 0.21% | — | Jetbrains Youtrack | 1/10/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group membership changes | |
| Analizada | Alta (8.1) | 0.22% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible | |
| Analizada | Media (6.5) | 0.68% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 doS attack was possible via crafted PSD attachments | |
| Analizada | Media (6.5) | 0.20% | — | Jetbrains Youtrack | 1/10/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19422 iDOR in the issue activities API allowed reading restricted issues | |
| Analizada | Alta (7.2) | 0.43% | — | Jetbrains Youtrack | 1/10/2026 | 5/10/2026 | In JetBrains YouTrack before 2026.2.19422 privilege escalation was possible via user group links | |
| Analizada | Media (5.4) | 0.34% | — | Jetbrains Youtrack | 1/10/2026 | 5/10/2026 | In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible | |
| Analizada | Alta (7.1) | 0.28% | — | Jetbrains Youtrack | 1/10/2026 | 5/10/2026 | In JetBrains YouTrack before 2026.2.19422 missing authorisation allowed authenticated users to add themselves to project teams and access restricted issues | |
| Aplazada | Alta (8.8) | 0.38% | — | Bytecore Stack MCP Connector FOR AI ToolsAI | 1/10/2026 | 3/10/2026 | The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's… | |
| Aplazada | Alta (7.2) | 0.33% | — | Mowgli AI AI EngineAI | 1/10/2026 | 1/10/2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.8.0 This is due to a chain of missing input neutralization and output escaping across the /mwai-ui/v1/chats/submit REST endpoint, the PHP error-log parser… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Stitionai DevikaAI | 30/9/2026 | 2/10/2026 | Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py. | |
| Aplazada | Crítica (9.8) | 0.40% | — | Stitionai DevikaAI | 30/9/2026 | 1/10/2026 | Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content. | |
| En análisis | Crítica (9.4) | 0.24% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is… | |
| En análisis | Media (5.3) | 0.36% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service. | |
| En análisis | Media (6.5) | 0.26% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither… | |
| En análisis | Media (6.6) | 0.41% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and… | |
| En análisis | Alta (7.2) | 0.39% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code… | |
| En análisis | Alta (7.2) | 0.39% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account. | |
| En análisis | Alta (7.5) | 0.21% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to… | |
| En análisis | Alta (7) | 0.19% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including… |