Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 25 respecto a la semana anterior
Críticas / altas1269▼ 244 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
14.295 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.35% | — | Helicone Ai-gatewayAI | 12/7/2026 | 13/7/2026 | A flaw has been found in Helicone ai-gateway up to 0.2.0-beta.30. This affects the function build_target_url of the file ai-gateway/src/dispatcher/service.rs of the component AWS Metadata Service. Executing a manipulation of the argument extracted_path_and_query can lead to server-side request forgery. The attack can… | |
| Analizada | Crítica (9.3) | 0.66% | — | Flowiseai Flowise | 12/7/2026 | 14/7/2026 | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the… | |
| Analizada | Alta (8.8) | 0.65% | — | Kidocode Crawl4ai | 12/7/2026 | 14/7/2026 | Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path parameter accepts arbitrary filesystem paths without validation, allowing an attacker to supply absolute or path-traversal values to write to any location writable by the… | |
| Analizada | Alta (8.8) | 0.43% | — | Kidocode Crawl4ai | 12/7/2026 | 14/7/2026 | Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls to attacker-controlled endpoints and read arbitrary environment variables. Attackers can exploit the unauthenticated /md, /llm, and /llm/job endpoints by supplying a malicious… | |
| Aplazada | Crítica (10) | 2.5% | 💥 Exploit | PraisonaiAI | 11/7/2026 | 13/7/2026 | PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and… | |
| Aplazada | Crítica (9.4) | 0.88% | — | PraisonaiAI | 11/7/2026 | 14/7/2026 | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization in LLM tool calls. Attackers can inject malicious prompts through the chat interface to write files to arbitrary filesystem locations and execute… | |
| Aplazada | Alta (7.1) | 0.46% | — | Praisonai PlatformAI | 11/7/2026 | 13/7/2026 | PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can modify owner-created records; for projects, a member can reassign lead_id to their own user id and then… | |
| Aplazada | Alta (8.7) | 0.43% | — | PraisonaiAI | 11/7/2026 | 14/7/2026 | PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that… | |
| Aplazada | Alta (8.4) | 0.35% | — | ChromiumAIPraisonaiAIKidocode Crawl4aiAI | 11/7/2026 | 13/7/2026 | PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend that allows attackers to bypass SSRF validation by exploiting DNS rebinding and HTTP redirects. Attackers can craft URLs that resolve to internal services after the initial validation check, enabling… | |
| Aplazada | Media (6.9) | 0.37% | — | Praisonai AgentmailAI | 11/7/2026 | 13/7/2026 | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to… | |
| Aplazada | Alta (8.8) | 0.48% | — | PraisonaiAI | 11/7/2026 | 13/7/2026 | PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication. | |
| Aplazada | Crítica (9.3) | 0.70% | — | PgvectorAIApache CassandraAIPraisonaiAI | 11/7/2026 | 14/7/2026 | PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated… | |
| Aplazada | Media (6.8) | 0.18% | — | PraisonaiAI | 11/7/2026 | 13/7/2026 | PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace. Attackers can include path traversal sequences like @../outside_secret.txt or absolute paths in project command files to exfiltrate process-readable files into model… | |
| Aplazada | Media (4.4) | 0.34% | — | Print PDF Email BY PrintfriendlyAI | 11/7/2026 | 13/7/2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.3) | 0.56% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 14/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft… | |
| Aplazada | Media (5.3) | 0.52% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 15/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's… | |
| Aplazada | Media (5.8) | 0.38% | — | Axllent MailpitAI | 10/7/2026 | 13/7/2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard library classification helpers and does not block IPv6 transition mechanisms or prefixes such as… | |
| Analizada | Media (5.4) | 0.23% | — | J-vee AI Seo/geo Analyzer | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AI SEO/GEO Analyzer allows Stored XSS. This issue affects AI SEO/GEO Analyzer versions: from 0.0.0 to 1.1.3. | |
| Analizada | Baja (3.3) | 0.21% | 💥 PoC | Openai Provider Project Openai Provider | 10/7/2026 | 6/8/2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal OpenAI Provider allows Server Side Request Forgery. This issue affects OpenAI Provider versions: from 0.0.0 to 1.1.1, from 1.2.0 to 1.2.2. | |
| Pendiente de análisis | Alta (7.6) | 0.47% | — | Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI | 10/7/2026 | 13/7/2026 | LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without… | |
| Aplazada | Alta (7.1) | 0.42% | — | Glpi DatainjectionAI | 10/7/2026 | 14/7/2026 | The DataInjection plugin for GLPI 2.15.6 (GLPI 11 builds) concatenates user-supplied CSV field values directly into SQL queries during CSV import, without parameterization or escaping, resulting in authenticated SQL injection. An authenticated user with access to the Data injection feature can embed SQL expressions… | |
| En análisis | Media (6.3) | 0.44% | — | Deloitte AI Assist FOR Customer | 10/7/2026 | 3/8/2026 | Deloitte AI Assist for Customer exposed unauthenticated API endpoints that allowed an attacker with knowledge of additional parameters to read from or inject content into the retrieval-augmented generation (RAG) corpus. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the… | |
| En análisis | Media (6.9) | 0.60% | — | Deloitte AI Assist FOR Customer | 10/7/2026 | 3/8/2026 | Deloitte AI Assist for Customer accepted unauthenticated POST requests through public-facing API endpoints that allowed a remote attacker to make limited additions to the configuration. These additions were not used by the system. On 2026-03-25, AI Assist for Customer restricted network access and enforced… | |
| Analizada | Media (6.9) | 0.51% | — | Deloitte AI Assist FOR Customer | 10/7/2026 | 21/7/2026 | Deloitte AI Assist for Customer disclosed some configuration information through public-facing API endpoints that accepted unauthenticated requests. This information could reduce an attacker’s reconnaissance effort. On 2026-03-25, AI Assist for Customer restricted network access and enforced authentication for the… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. |