Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
14.266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.35% | — | Sourcecodester AIR Cargo Management SystemAI | 14/8/2026 | 14/8/2026 | A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Alta (7.3) | 3.7% | — | Baicells Eg3661mAIOpenwrt LuciAI | 14/8/2026 | 18/8/2026 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 0.41% | — | Raisecom Communication Command AND Dispatch Management PlatformAI | 14/8/2026 | 14/8/2026 | A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the file /app/users/getpwd.php. Such manipulation of the argument sip leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might… | |
| Aplazada | Media (5.1) | 0.56% | — | Dtstack TaierAI | 14/8/2026 | 18/8/2026 | A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to… | |
| Aplazada | Media (5.5) | 0.61% | — | Dtstack TaierAI | 14/8/2026 | 14/8/2026 | A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the component Chunk-Check Endpoint. The manipulation of the argument Name results in path traversal. The attack may be launched remotely. The exploit has been made public… | |
| Aplazada | Media (5.1) | 0.51% | — | Dtstack TaierAI | 14/8/2026 | 14/8/2026 | A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the file UploadController.java of the component Upload Controller. The manipulation of the argument File leads to path traversal. The attack may be initiated remotely. Upgrading to version 1.5.0 is able… | |
| Aplazada | Media (5.1) | 0.26% | — | Next AI Draw.ioAI | 13/8/2026 | 9/9/2026 | Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without escaping into HTML and JavaScript. Attackers can craft malicious URLs to execute arbitrary JavaScript in the localhost origin, enabling exfiltration of diagram sessions… | |
| Aplazada | Alta (7.7) | 0.43% | — | Next AI Draw.ioAI | 13/8/2026 | 9/9/2026 | Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation that only checks string patterns without DNS resolution. Unauthenticated attackers can supply hostnames that bypass string validation but resolve to internal addresses,… | |
| Aplazada | Alta (8.6) | 0.26% | — | RainbondAI | 13/8/2026 | 9/9/2026 | Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token to bypass enterprise ID verification and… | |
| Pendiente de análisis | Media (5.1) | 0.55% | — | Rails Html SanitizerAI | 13/8/2026 | 18/9/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 13/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant. Such unauthorized access could enable… | |
| Aplazada | Alta (7.6) | 0.38% | — | Mailchimp FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Arvow AI SEO WriterAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in Arvow AI SEO Writer <= 1.5.3 versions. | |
| Aplazada | Media (6.5) | 0.33% | — | AI FOR SEOAI | 13/8/2026 | 14/8/2026 | Unauthenticated Broken Access Control in AI for SEO <= 2.4.2 versions. | |
| Aplazada | Alta (7.7) | 0.44% | — | AI HUBAI | 13/8/2026 | 14/8/2026 | Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Knowledge Base FOR Documentation Faqs With AI AssistanceAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Knowledge Base for Documentation, FAQs with AI Assistance <= 17.211.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mailchimp Subscribe FormsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | |
| Aplazada | Media (4.3) | 0.29% | — | HCL AionAI | 13/8/2026 | 28/8/2026 | HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions. | |
| Pendiente de análisis | Alta (8.7) | 0.65% | — | Network-aiAI | 13/8/2026 | 9/9/2026 | Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes preserved while the executor tokenizes commands by stripping quotes before execution. Attackers can craft quoted commands that evade blocklist checks and approval gates while… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Network-ai ClaudehookbridgeAIAnthropic Claude CodeAI | 13/8/2026 | 9/9/2026 | Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes the full untruncated command. Attackers can position dangerous content past byte 500 in a Bash command field to bypass the operator's hard-deny list and execute arbitrary… | |
| Analizada | Alta (7.1) | 0.41% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud… | |
| Analizada | Media (6.3) | 0.33% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID,… | |
| Analizada | Crítica (9) | 0.83% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute… |