Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.44% | — | Argo WorkflowsAI | 19/9/2026 | 22/9/2026 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field… | |
| Pendiente de análisis | Alta (7.5) | 0.44% | 💥 PoC | Apache AirflowAI | 18/9/2026 | 22/9/2026 | Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently suppressing asset-triggered scheduling for it — a state-changing action gated on a… | |
| Aplazada | Alta (8.3) | 0.43% | 💥 PoC | ItflowAI | 17/9/2026 | 24/9/2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform time-based blind SQL injection through the expires parameter of the… | |
| Aplazada | Alta (8.1) | 0.48% | 💥 PoC | ItflowAI | 17/9/2026 | 30/9/2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the frequency parameter handled by agent/post/recurring_invoice.php. The handler… | |
| Aplazada | Media (5.3) | 0.51% | — | Infiniflow RagflowAI | 17/9/2026 | 21/9/2026 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing… | |
| Modificada | Media (6.5) | 0.81% | — | Apache-airflow-providers-akeyless | 16/9/2026 | 17/9/2026 | Apache Airflow Akeyless provider: the Akeyless secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path separator that causes the backend to resolve a secret belonging to a different team,… | |
| Analizada | Alta (8.8) | 1.2% | — | Apache-airflow-providers-apache-kafka | 16/9/2026 | 18/9/2026 | Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer… | |
| Analizada | Alta (8.1) | 0.37% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: the Authentik OAuth path in the FAB auth manager does not validate the issuer or audience claims of the id_token it accepts. An attacker holding a token that the same Authentik identity provider minted for a different client application can present it to Airflow and be authenticated as the… | |
| Analizada | Alta (7.2) | 1.0% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: deactivating a user account does not stop tokens issued to that account before deactivation. Password authentication correctly rejects the disabled account, but the Core API continues to accept an existing, unexpired token naming it, and lets that token mint a replacement — so the account… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: the unauthenticated token endpoint accepts a client-credentials grant for any confidential client registered in the Keycloak realm, not only the client configured for Airflow. No allowlist restricts which client ids may authenticate, so the credentials of an unrelated application that… | |
| Analizada | Crítica (9.1) | 0.81% | — | Apache-airflow-providers-keycloak | 16/9/2026 | 18/9/2026 | Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak auth manager takes a user's identity from the signed Airflow session token but takes the Keycloak access and refresh tokens used for every authorization decision from separate, unauthenticated cookies, and never checks that the two describe the same… | |
| Analizada | Crítica (9.1) | 0.83% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH endpoint does not invalidate that user's existing database-backed sessions. An attacker who already holds a copy of the victim's session cookie keeps full access as that user after the password change, so the password reset does… | |
| Analizada | Crítica (9.8) | 0.98% | — | Apache-airflow-providers-fab | 16/9/2026 | 18/9/2026 | Apache Airflow FAB provider: resetting a user's password does not delete that user's existing database-backed sessions, despite documented behaviour that it does. The cleanup compares the string identifier Flask-Login stores in the session against the user's integer database identifier, so the comparison never matches… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resource. | |
| Pendiente de análisis | Media (5.4) | 0.17% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | |
| Pendiente de análisis | Alta (7.6) | 0.37% | — | CheerioAIMicrosoft PlaywrightAIPuppeteerAIFlowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network resources with response content returned as… | |
| Pendiente de análisis | Alta (8.3) | 0.46% | — | Flowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like tag_version and node_version to execute… | |
| Pendiente de análisis | Alta (8.7) | 0.74% | — | Flowiseai FlowiseAI | 15/9/2026 | 16/9/2026 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the web root to execute commands or perform… | |
| Pendiente de análisis | Alta (7.6) | 0.35% | — | Flowiseai FlowiseAI | 15/9/2026 | 17/9/2026 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve tool definitions and execute tools from… | |
| Pendiente de análisis | Crítica (9) | 0.73% | — | Flowiseai FlowiseAI | 15/9/2026 | 16/9/2026 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling the working directory to execute… | |
| Aplazada | Alta (8.7) | 0.47% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection. | |
| Pendiente de análisis | Alta (8.7) | 0.39% | — | Flowiseai FlowiseAI | 15/9/2026 | 19/9/2026 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to cloud metadata services or internal hosts. | |
| Aplazada | Crítica (9) | 0.68% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm packages to execute code on the Flowise server. | |
| Aplazada | Alta (7.7) | 0.40% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative access to victim organizations by… | |
| Aplazada | Alta (7.6) | 0.35% | — | Flowiseai FlowiseAI | 15/9/2026 | 23/9/2026 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org roles, and abuse stored SSO secrets. |