Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
14.268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.46% | 💥 PoC | Flowiseai Flowise | 8/8/2026 | 4/9/2026 | Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_LIST omits the Oracle Cloud Infrastructure metadata endpoint 192.0.0.192 and the Alibaba Cloud metadata endpoint 100.100.100.200, allowing authenticated attackers to force… | |
| Aplazada | Media (5) | 0.34% | — | AI EngineAI | 8/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level… | |
| Aplazada | Media (4.8) | 0.27% | — | AI EngineAI | 8/8/2026 | 26/8/2026 | The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deletion, authorising the action solely by a client-supplied session cookie value, so an unauthenticated attacker who obtains a victim's session identifier and file reference can delete that victim's… | |
| Aplazada | Crítica (9.8) | 0.91% | — | AI Copilot Content GeneratorAI | 8/8/2026 | 12/8/2026 | The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to create a new… | |
| Aplazada | Media (5.7) | 0.18% | — | Katacontainers Kata ContainersAI | 7/8/2026 | 9/9/2026 | Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent enforces an… | |
| Aplazada | Crítica (9.2) | 0.20% | — | Katacontainers Kata ContainersAI | 7/8/2026 | 9/9/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. In this configuration, Kata runs the host virtiofsd as root… | |
| Aplazada | Crítica (9.6) | 0.61% | — | Katacontainers Kata RuntimeAI | 7/8/2026 | 9/9/2026 | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary… | |
| Aplazada | Alta (8.8) | 0.44% | — | Praisonai Platform APIAI | 7/8/2026 | 18/9/2026 | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read,… | |
| Aplazada | Media (6.9) | 0.40% | — | AIL Project AILAI | 6/8/2026 | 26/8/2026 | AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and post identifiers directly into inline JavaScript onclick handlers: onclick="translateMessageToPreferredLanguage('{{ message['id'] }}',… | |
| Aplazada | Media (6.9) | 0.40% | — | AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to display a stored screenshot, without context-appropriate encoding. An attacker who can cause a specially crafted URL to be recorded in the… | |
| Aplazada | Alta (8.2) | 0.40% | — | Circl AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error… | |
| Pendiente de análisis | Media (5.3) | 0.53% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Radar Diagrams allow arbitrary large values for the ticks parameter, which can cause high CPU usage and freeze the rendering webpage or JavaScript process for long periods… | |
| Pendiente de análisis | Baja (2.4) | 0.35% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid's configuration setters (mermaid.initialize, mermaidAPI.setConfig, and mermaidAPI.updateSiteConfig) merge caller-supplied configuration into Mermaid's internal config using the… | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Architecture Diagrams are vulnerable to prototype pollution when a diagram defines a group with an id of __proto__. Because the group id is used directly as an object… | |
| Pendiente de análisis | Media (5.3) | 0.58% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1, Mermaid XY Charts are vulnerable to an infinite loop denial of service in the setXAxisRangeData function when configuring an X-Axis with invalid parameters. Because each… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langchain Langgraph Checkpoint PostgresAILangchain Langgraph Checkpoint SqliteAI | 6/8/2026 | 10/9/2026 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string… | |
| Analizada | Alta (8.7) | 0.66% | — | Flowiseai Flowise | 6/8/2026 | 15/9/2026 | Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST… | |
| Analizada | Alta (8.5) | 0.48% | — | Flowiseai Flowise | 6/8/2026 | 15/9/2026 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without workspace ownership verification.… | |
| Analizada | Alta (7.2) | 0.42% | — | Flowiseai Flowise | 6/8/2026 | 15/9/2026 | Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document store operations by accessing unprotected mutation endpoints. Attackers holding only view-level permissions can send direct HTTP requests to the upsert and refresh document… | |
| Pendiente de análisis | Media (5.3) | 0.60% | — | MermaidAI | 6/8/2026 | 8/9/2026 | Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary… | |
| Aplazada | Media (5.9) | 0.16% | — | Ayecode GetpaidAI | 6/8/2026 | 26/8/2026 | The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made. | |
| Aplazada | Alta (8.6) | 0.41% | — | Constantcontact Creative MailAI | 6/8/2026 | 26/8/2026 | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | |
| Aplazada | Media (6.5) | 0.22% | — | MailoptinAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | AI ANNAI | 6/8/2026 | 12/8/2026 | Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions. |