Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3950 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.35% | — | Tduckcloud Tduck-platformAI | 13/9/2026 | 14/9/2026 | A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is… | |
| Aplazada | Media (6.1) | 0.26% | — | IBM Marketing PlatformAI | 11/9/2026 | 22/9/2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter. | |
| Pendiente de análisis | Crítica (9.2) | 0.44% | — | Akana API PlatformAI | 11/9/2026 | 18/9/2026 | A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Crítica (10) | 1.4% | — | Akana API PlatformAI | 9/9/2026 | 9/9/2026 | An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | SAP NetweaverAISAP Abap PlatformAI | 8/9/2026 | 8/9/2026 | Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details,… | |
| Pendiente de análisis | Alta (7.7) | 0.43% | — | SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI | 8/9/2026 | 9/9/2026 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high… | |
| Analizada | Crítica (9.9) | 0.63% | — | Microsoft Power Platform | 3/9/2026 | 8/9/2026 | Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.8) | 0.46% | — | Openedx Open EDX PlatformAI | 2/9/2026 | 9/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allow_redirects=True)". The fetched bytes are then returned inside a ZIP response. This enables SSRF with… | |
| Aplazada | Media (4.7) | 0.28% | — | Openedx PlatformAI | 2/9/2026 | 9/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The validate_timestamp_and_nonce function in… | |
| Aplazada | Alta (7.6) | 0.40% | — | Openedx Open EDX PlatformAI | 2/9/2026 | 9/9/2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated… | |
| Pendiente de análisis | Media (6.4) | 0.30% | — | Redhat Ansible Automation PlatformAIAnsible AWXAI | 1/9/2026 | 24/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A… | |
| Aplazada | Baja (3.5) | 0.27% | — | Runzero PlatformAI | 1/9/2026 | 9/9/2026 | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low). | |
| Aplazada | Alta (8.7) | 0.47% | — | Rust-iot-platformAI | 29/8/2026 | 23/9/2026 | rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Rust-iot-platformAI | 29/8/2026 | 23/9/2026 | rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without… | |
| Aplazada | Media (6.1) | 0.25% | — | Dayneks Software Industry AND Trade INC E-commerce PlatformAI | 28/8/2026 | 31/8/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Pendiente de análisis | Alta (8.8) | 0.25% | — | Pega PlatformAI | 28/8/2026 | 8/9/2026 | Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping. | |
| Pendiente de análisis | Crítica (10) | 0.42% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Pendiente de análisis | Crítica (10) | 0.62% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. ServiceNow… | |
| Pendiente de análisis | Crítica (10) | 5.0% | — | Servicenow AI PlatformAI | 27/8/2026 | 3/9/2026 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a… | |
| Pendiente de análisis | Crítica (10) | 7.2% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.… | |
| Aplazada | Alta (8.7) | 0.43% | — | Airbyte PlatformAI | 25/8/2026 | 24/9/2026 | Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace consults X-Airbyte-Workspace-Id ahead of… | |
| Aplazada | Media (6.2) | 0.44% | — | Hepta Platforms INC HeptabaseAI | 24/8/2026 | 26/8/2026 | Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Automation WEB Platform Notifications AND OTP FOR WoocommerceAI | 21/8/2026 | 24/8/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Commerce Platform | 18/8/2026 | 1/9/2026 | Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the… |