Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.16% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework… | |
| Analizada | Alta (8.4) | 0.14% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes… | |
| Analizada | Alta (8.5) | 0.30% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework.… | |
| Analizada | Media (6.7) | 0.24% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware… | |
| Analizada | Media (6.8) | 0.42% | — | Oracle Autonomous Health Framework | 18/8/2026 | 26/8/2026 | Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where… | |
| Aplazada | Media (6.1) | 0.36% | — | Beta Systems Software AG Anow AutomateAI | 18/8/2026 | 9/9/2026 | Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to execute arbitrary code | |
| Aplazada | Alta (7.1) | 0.25% | — | AutopayAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions. | |
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Redhat Ansible Automation PlatformAIHashicorp VaultAI | 18/8/2026 | 24/9/2026 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role… | |
| Aplazada | Baja (2.9) | 0.49% | — | AutomadAI | 17/8/2026 | 20/8/2026 | A vulnerability was determined in automad up to 2.0.0-beta.32. This vulnerability affects the function requestPasswordResetToken of the file automad/src/server/Controllers/API/UserController.php of the component Password Reset Endpoint. This manipulation of the argument name-or-email causes observable response… | |
| Analizada | Media (5.5) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate… | |
| Analizada | Alta (7.8) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. | |
| Analizada | Media (5.4) | 0.16% | — | Intel Hardware-aware-automated-machine-learning | 11/8/2026 | 2/10/2026 | Uncontrolled search path for some Hardware-Aware-Automated-MachineLearning NA before version 45cd723 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Alta (8.2) | 0.48% | — | AutogptAI | 11/8/2026 | 9/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL… | |
| Aplazada | Alta (7.7) | 0.35% | — | AutomatischAI | 10/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authenticated user with 'manage Flow' permission to make the server fetch arbitrary URLs and retrieve the full response body via the HTTP Request app's Custom Request action. | |
| Pendiente de análisis | Media (5.1) | 0.13% | — | Samsung Pass AutofillAI | 10/8/2026 | 18/8/2026 | Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | |
| Aplazada | Alta (8.8) | 0.51% | — | AutopayAI | 10/8/2026 | 26/8/2026 | The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that executes in the browser of any user,… | |
| Aplazada | Alta (8.1) | 0.47% | — | Autonetv RelayAI | 10/8/2026 | 26/8/2026 | The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes before the HTTP response is committed,… | |
| Aplazada | Media (5.1) | 0.38% | — | NXP Auto GoldvipAI | 9/8/2026 | 12/8/2026 | A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely. Upgrading to version 1.15.0 can resolve this… | |
| Aplazada | Baja (1.9) | 0.17% | — | Automateyournetwork McpyatsAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mcp_servers/mermaid/index.ts of the component generate_mermaid_markdown. The manipulation of the argument folder/name leads to path traversal. The attack must be carried… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mz-automation Libiec61850AI | 8/8/2026 | 12/8/2026 | A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReference of the file src/iec61850/common/iec61850_common.c of the component MMS Protocol Workflow. Such manipulation of the argument… | |
| Aplazada | Baja (1.9) | 0.17% | — | Mz-automation Libiec61850AI | 7/8/2026 | 12/8/2026 | A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopThreadless of the file src/sampled_values/sv_subscriber.c of the component ASDU Element Handler. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a… | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Revit | 6/8/2026 | 17/9/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Revit | 6/8/2026 | 17/9/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process. | |
| Aplazada | Baja (1.9) | 0.16% | — | Mz-automation Libiec61850AI | 6/8/2026 | 12/8/2026 | A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The attack needs to be approached locally. The… | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Revit | 6/8/2026 | 17/9/2026 | A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. |