Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.14% | — | NextflowAI | 15/9/2026 | 30/9/2026 | Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.writeConfig in… | |
| Pendiente de análisis | Crítica (9.6) | 0.43% | 💥 PoC | IBM LangflowAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role permissions, (2) arbitrary file… | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Alta (7.1) | 0.46% | — | Flowable-engineAI | 14/9/2026 | 24/9/2026 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external… | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM LangflowAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Pendiente de análisis | Media (4.2) | 0.15% | — | IBM LangflowAIIBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component. | |
| Pendiente de análisis | Media (5.4) | 0.34% | — | IBM Langflow OSSAI | 14/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to change the password of an account due to improper authentication. | |
| Analizada | Baja (2.1) | 0.41% | — | Flowiseai Flowise | 13/9/2026 | 16/9/2026 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results in server-side request forgery. The… | |
| Analizada | Media (6.3) | 0.48% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise versions before 3.1.4 contain an unauthenticated denial of service vulnerability in the /api/v1/text-to-speech/abort endpoint that accepts user-supplied chatflowId and chatId without ownership verification. Attackers can terminate active chatflow predictions for any user by submitting requests with known… | |
| Analizada | Media (6.1) | 0.37% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise is a low-code platform for building LLM applications. In versions up to and including 3.1.3, the POST /api/v1/node-load-method/:name endpoint is mounted without any route-level permission check and invokes component loadMethods with an attacker-controlled nodeName, loadMethod, inputs, and credential value. The… | |
| Analizada | Media (6) | 0.34% | — | Flowiseai Flowise | 12/9/2026 | 15/9/2026 | Flowise before 3.1.4 contains a broken access control vulnerability in GET /api/v1/organizationuser that allows any authenticated organization member to retrieve the organization owner's full user record including bcrypt password hash and temporary tokens. Attackers can query the endpoint with any user ID to obtain… | |
| Analizada | Alta (8.8) | 0.85% | — | Langflow | 10/9/2026 | 14/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Alta (8.8) | 0.63% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses… | |
| Analizada | Alta (8.8) | 0.81% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. | |
| Analizada | Alta (8.1) | 0.43% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. | |
| Analizada | Alta (7.5) | 0.39% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5. | |
| Analizada | Alta (8.6) | 0.49% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. | |
| Analizada | Alta (8.8) | 0.50% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. | |
| Analizada | Crítica (9.8) | 0.86% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. | |
| Analizada | Alta (8.8) | 0.81% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. | |
| Analizada | Media (6.5) | 0.41% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control. | |
| Analizada | Crítica (9.8) | 0.67% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. |