Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▲ 64 respecto a la semana anterior
Críticas / altas1288▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
14.295 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.61% | — | Jetbrains Youtrack | 14/7/2026 | 12/8/2026 | In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible | |
| Aplazada | Alta (8.1) | 0.47% | — | AI EngineAI | 14/7/2026 | 14/7/2026 | The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenticated users with editor-level access to write attacker-controlled bytes to an arbitrary location on the server via path traversal. | |
| Aplazada | Media (5.9) | 0.29% | — | Brainstormforce SureformsAI | 14/7/2026 | 14/7/2026 | The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden) payment amount, allowing unauthenticated users to underpay for the configured product or subscription. Forms using a fixed configured price are not affected. | |
| Aplazada | Media (5.5) | 0.59% | — | Poco-ai Poco-clawAI | 14/7/2026 | 14/7/2026 | A flaw has been found in poco-ai poco-claw up to 0.5.4. Affected is the function get_workspace_file of the file executor_manager/app/api/v1/workspace.py of the component Workspace API. Executing a manipulation of the argument user_id can lead to authorization bypass. The attack may be launched remotely. The exploit… | |
| Analizada | Alta (8.3) | 0.52% | — | Crewai | 13/7/2026 | 17/9/2026 | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS… | |
| Aplazada | Baja (2.9) | 0.46% | — | Waooai WaoowaooAI | 13/7/2026 | 15/7/2026 | A vulnerability was found in waooAI waoowaoo up to 0.4.1. Impacted is the function stablePublicIdFromStorageKey in the library src/lib/media/hash.ts of the component Media Handler. The manipulation of the argument storageKey results in improper authorization. The attack may be performed from remote. The attack… | |
| Pendiente de análisis | Crítica (9.5) | 1.4% | 💥 Exploit | Servicenow AI PlatformAI | 13/7/2026 | 14/7/2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to… | |
| Modificada | Alta (8.1) | 0.60% | — | Apache-airflow-providers-fab | 13/7/2026 | 16/9/2026 | In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs permission (privilege escalation). The escalation triggers… | |
| Modificada | Alta (8.1) | 0.74% | — | Apache-airflow-providers-git | 13/7/2026 | 16/9/2026 | The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling SSH host-key verification. An attacker who can intercept the network path between an Airflow worker and the Git server can impersonate the server (man-in-the-middle), capturing the SSH deploy key or… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Sergey Aiwu Ai-copilot-content-generatorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through <= 1.5.4. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Properfraction MailoptinAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3. | |
| Aplazada | Alta (7.5) | 0.51% | — | Select-themes SetsailAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes SetSail setsail allows PHP Local File Inclusion.This issue affects SetSail: from n/a through <= 2.1. | |
| Aplazada | Alta (7.5) | 0.51% | — | Jetbrains AquaAI | 13/7/2026 | 13/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Acymailing Newsletter Team Acymailing Smtp NewsletterAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Stored XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0. | |
| Aplazada | Alta (7.1) | 0.32% | — | Acymailing Smtp NewsletterAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.1. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Acymailing Smtp NewsletterAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through <= 10.11.0. | |
| Aplazada | Crítica (10) | 0.52% | — | Coderevolution Aimogen PROAI | 13/7/2026 | 13/7/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Siteground Email MarketingAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5. | |
| Aplazada | Alta (8.8) | 0.42% | — | MailerpressAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2. | |
| Aplazada | Media (6.5) | 0.33% | — | Roxnor Wp-fundraising-donationAIWpmet FundengineAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FundEngine: from n/a through <= 1.7.6. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Brainstormforce SuredashAI | 13/7/2026 | 13/7/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through <= 1.8.0. | |
| Aplazada | Media (5.5) | 0.69% | — | Waooai WaoowaooAI | 13/7/2026 | 13/7/2026 | A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/requireUserAuth/requireProjectAuth/requireProjectAuthLight in the library src/lib/api-auth.ts of the component Internal Task Header Handler. This manipulation of the… | |
| Aplazada | Media (6.9) | 0.70% | — | Will-moss IsaiahAI | 13/7/2026 | 15/7/2026 | A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection Authentication. The manipulation leads to improper authentication. The attack can be initiated remotely. The pull request to fix this issue awaits acceptance. | |
| Aplazada | Media (6.9) | 0.54% | — | Will-moss IsaiahAI | 13/7/2026 | 13/7/2026 | A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component Master Websocket Handler. Executing a manipulation of the argument Agent can lead to missing authorization. It is possible to launch the attack remotely.… | |
| Aplazada | Baja (2.1) | 0.43% | — | Akariasai Self RAGAI | 13/7/2026 | 13/7/2026 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to… |