Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2685▼ 177 respecto a la semana anterior
Críticas / altas1223▼ 305 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
14.266 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9) | 1.1% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment… | |
| Analizada | Media (6) | 0.37% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable… | |
| Analizada | Crítica (9) | 0.96% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal… | |
| Analizada | Crítica (9) | 0.66% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the… | |
| Analizada | Crítica (9) | 0.60% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to… | |
| Analizada | Alta (8.6) | 0.43% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem. | |
| Analizada | Crítica (9.4) | 0.62% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to… | |
| Aplazada | Baja (3.7) | 0.12% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION está afectado por una vulnerabilidad donde las respuestas JavaScript que contienen datos podrían ser referenciadas por páginas externas, lo que podría permitir que información sensible sea capturada por una página controlada por un atacante (secuestro de JavaScript) bajo ciertas condiciones. | |
| Aplazada | Baja (3.4) | 0.21% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION está afectado por una vulnerabilidad donde ciertos campos de entrada no aplican suficiente validación de entrada del lado del servidor. La aplicación puede aceptar entradas inesperadas o manipuladas, lo que podría resultar en un comportamiento no deseado o impacto en la seguridad bajo ciertas condiciones. | |
| Aplazada | Media (5.6) | 0.15% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION se ve afectado por una vulnerabilidad donde ciertos puntos finales carecen de controles antiautomatización suficientes. Se pueden enviar solicitudes automatizadas o mediante scripts sin una limitación de velocidad o mecanismos de desafío adecuados, lo que podría resultar en un comportamiento no deseado o un… | |
| Aplazada | Media (4.7) | 0.11% | — | HCL AionAI | 13/8/2026 | 29/9/2026 | HCL AION está afectado por una vulnerabilidad donde el almacenamiento compartido utilizado por los componentes del producto está diseñado sin suficiente separación de acceso. Los procesos que comparten el almacenamiento pueden ser capaces de acceder o modificar archivos más allá de su alcance previsto, lo que podría… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 13/8/2026 | 26/8/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 18/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack. | |
| Analizada | Alta (8.1) | 0.35% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |
| Analizada | Alta (8.1) | 0.45% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a… | |
| Analizada | Alta (8.7) | 0.49% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by… | |
| Analizada | Baja (3.1) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack. | |
| Analizada | Alta (7.4) | 0.32% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Pendiente de análisis | Alta (8.7) | 0.97% | — | Microsoft Container Migration Solution AcceleratorAI | 12/8/2026 | 18/9/2026 | The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration… | |
| Analizada | Media (6.5) | 0.33% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by… | |
| Analizada | Media (6.5) | 0.23% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was… | |
| Analizada | Media (6.5) | 0.36% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two… |