Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
14.240 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Crítica (9.1) | 0.34% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.23% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.23% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Crítica (9.1) | 0.27% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| En análisis | Alta (7.2) | 0.71% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary… | |
| En análisis | Crítica (9.1) | 0.27% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could… | |
| En análisis | Alta (7.2) | 0.47% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load… | |
| En análisis | Alta (7.2) | 0.50% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system. | |
| Aplazada | Alta (8.7) | 0.55% | — | Inspur Haiyue HCM CloudAI | 30/9/2026 | 1/10/2026 | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as… | |
| Aplazada | Alta (8.1) | 0.34% | 💥 PoC | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.31.3, when the OIDC login flow completes, backend/modules/auth/providers/auth_oidc_provider.py decodes the id_token returned by the identity provider's token endpoint using jose.jwt.get_unverified_claims() instead of… | |
| Aplazada | Crítica (9.1) | 0.35% | — | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a… | |
| Aplazada | Crítica (9.8) | 0.64% | 💥 PoC | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature… | |
| Aplazada | Crítica (9.4) | 0.60% | — | Quenary TugtainerAI | 30/9/2026 | 30/9/2026 | Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts… | |
| Analizada | Media (4.3) | 0.17% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible | |
| Analizada | Media (6.5) | 0.25% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials | |
| Analizada | Media (4.9) | 0.24% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments | |
| Analizada | Crítica (9.8) | 0.28% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature | |
| Analizada | Alta (7.5) | 0.22% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action | |
| Analizada | Media (4.8) | 0.19% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible | |
| Analizada | Media (6.5) | 0.84% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template | |
| Analizada | Crítica (9.8) | 0.30% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution | |
| Analizada | Media (4.9) | 0.29% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read restricted issues | |
| Analizada | Baja (2.7) | 0.23% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from other projects | |
| Analizada | Baja (2.7) | 0.17% | — | Jetbrains Youtrack | 30/9/2026 | 2/10/2026 | In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurations | |
| Analizada | Media (4.3) | 0.20% | — | Jetbrains Youtrack | 30/9/2026 | 1/10/2026 | In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed |