Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3950 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.35%—Tduckcloud Tduck-platformAI13/9/202614/9/2026
A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is…
AplazadaMedia (6.1)0.26%—IBM Marketing PlatformAI11/9/202622/9/2026
A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter.
Pendiente de análisisCrítica (9.2)0.44%—Akana API PlatformAI11/9/202618/9/2026
A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a…
Pendiente de análisisAlta (8.7)0.27%—Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI11/9/202611/9/2026
A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users…
AplazadaCrítica (10)1.4%—Akana API PlatformAI9/9/20269/9/2026
An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to bypass authentication and reach an endpoint that evaluates attacker-supplied…
Pendiente de análisisMedia (4.3)0.28%—SAP NetweaverAISAP Abap PlatformAI8/9/20268/9/2026
Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration information. Successful exploitation could result in exposure of security relevant settings and internal system details,…
Pendiente de análisisAlta (7.7)0.43%—SAP Netweaver Application Server FOR AbapAISAP Abap PlatformAI8/9/20269/9/2026
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high…
AnalizadaCrítica (9.9)0.63%—Microsoft Power Platform3/9/20268/9/2026
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (6.8)0.46%—Openedx Open EDX PlatformAI2/9/20269/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a server-side fetch using "requests.get(url, allow_redirects=True)". The fetched bytes are then returned inside a ZIP response. This enables SSRF with…
AplazadaMedia (4.7)0.28%—Openedx PlatformAI2/9/20269/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The validate_timestamp_and_nonce function in…
AplazadaAlta (7.6)0.40%—Openedx Open EDX PlatformAI2/9/20269/9/2026
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 59bb6d6, the view function set_course_mode_price() at lms/djangoapps/instructor/views/instructor_dashboard.py:430 is decorated only with @login_required and performs no course-level permission check. Any authenticated…
Pendiente de análisisMedia (6.4)0.30%—Redhat Ansible Automation PlatformAIAnsible AWXAI1/9/202624/9/2026
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A…
AplazadaBaja (3.5)0.27%—Runzero PlatformAI1/9/20269/9/2026
An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an instance of CWE-639: Authorization Bypass Through User-Controlled Key and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N (3.5 Low).
AplazadaAlta (8.7)0.47%—Rust-iot-platformAI29/8/202623/9/2026
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
AplazadaCrítica (9.3)0.83%—Rust-iot-platformAI29/8/202623/9/2026
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without…
AplazadaMedia (6.1)0.25%—Dayneks Software Industry AND Trade INC E-commerce PlatformAI28/8/202631/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted early about this disclosure but did not…
Pendiente de análisisAlta (8.8)0.25%—Pega PlatformAI28/8/20268/9/2026
Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.
Pendiente de análisisCrítica (10)0.42%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data…
Pendiente de análisisCrítica (10)0.62%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. ServiceNow…
Pendiente de análisisCrítica (10)5.0%—Servicenow AI PlatformAI27/8/20263/9/2026
ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a…
Pendiente de análisisCrítica (10)7.2%—Servicenow AI PlatformAI27/8/20261/9/2026
ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.…
AplazadaAlta (8.7)0.43%—Airbyte PlatformAI25/8/202624/9/2026
Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace consults X-Airbyte-Workspace-Id ahead of…
AplazadaMedia (6.2)0.44%—Hepta Platforms INC HeptabaseAI24/8/202626/8/2026
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
AnalizadaAlta (7.5)0.33%—Oracle Commerce Platform18/8/20261/9/2026
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Dynamo Application Framework). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the…