Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2731▼ 12 respecto a la semana anterior
Críticas / altas1272▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

14.295 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.45%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Pendiente de análisisCrítica (9.3)0.43%—Guardrails-detectorsAI10/7/202631/8/2026
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially…
AnalizadaMedia (6.1)0.66%—Jetbrains Youtrack10/7/202610/7/2026
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
AplazadaCrítica (9.4)0.57%—PraisonaiAI10/7/202610/7/2026
PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs via subprocess.Popen().
AplazadaAlta (7.1)0.41%—Praisonai PlatformAI10/7/202610/7/2026
PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who cannot delete a dependency through an…
AplazadaAlta (8.5)0.17%—PraisonaiagentsAI10/7/202614/7/2026
PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and imports a sibling…
AplazadaAlta (8.7)0.88%—PraisonaiAI10/7/202610/7/2026
PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted commands via find's built-in -exec, -execdir, and -delete actions. Attackers can craft find commands with these built-in actions to read blocked files, delete files, or…
AplazadaMedia (6.9)0.41%—PraisonaiagentsAI10/7/202610/7/2026
PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor canonicalizes joined paths before enforcing…
AplazadaMedia (6.8)0.35%—PraisonaiAI10/7/202610/7/2026
PraisonAI before 4.6.78 contains a path traversal vulnerability in ContextGatherer that fails to validate include paths in .praisoncontext and .praisoninclude files. Attackers can supply absolute paths or parent directory traversal sequences to read arbitrary files outside the workspace and include their contents in…
AplazadaMedia (6.9)0.30%—PraisonaiAI10/7/202610/7/2026
PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url parameter is validated at request time but re-resolved at connection time, allowing attackers to use DNS rebinding to reach internal services with a blind SSRF attack.
AplazadaMedia (6.9)0.14%—PraisonaiagentsAI10/7/202610/7/2026
PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the…
AplazadaMedia (6.9)0.36%—PraisonaiAI10/7/202614/7/2026
PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITICAL, requiring three or more detector families to match simultaneously. Attackers can craft single or double-vector prompt injections that are classified as HIGH threat…
AnalizadaAlta (8.1)0.35%—Jetbrains Teamcity10/7/202614/7/2026
In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks
AnalizadaMedia (6.1)0.34%—Jetbrains Teamcity10/7/202613/7/2026
In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible
AnalizadaMedia (5.4)0.32%—Jetbrains Teamcity10/7/202610/7/2026
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
AnalizadaAlta (8.8)0.49%—Jetbrains Teamcity10/7/202614/7/2026
In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration
AnalizadaCrítica (9.8)0.60%—Jetbrains Intellij Idea10/7/202614/7/2026
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
AnalizadaBaja (3.5)0.23%—Jetbrains Youtrack10/7/202610/7/2026
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
AnalizadaCrítica (9.2)0.51%—Kidocode Crawl4ai10/7/202613/7/2026
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata…
AplazadaMedia (4.9)0.51%—Mail MintAI10/7/202614/7/2026
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter in all versions up to, and including, 1.24.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
AplazadaMedia (4.3)0.39%—GW AI Website BuilderAI10/7/202614/7/2026
The GW AI Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gwaiwebu_gravitywrite_disconnect_handler() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access…
Pendiente de análisisCrítica (9.3)0.53%—Guardrails-detectorsAI10/7/202630/9/2026
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from…
AplazadaMedia (5.1)0.16%—Samsung EmailAI10/7/202610/7/2026
Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox.
AplazadaMedia (6.1)0.36%—Brevo Newsletter Smtp Email Marketing Subscribe FormsAI10/7/202610/7/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaMedia (4.3)0.37%—Kadencewp Gutenberg Blocks With AIAI10/7/202610/7/2026
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API…