Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5) | 0.35% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints. | |
| Analizada | Alta (8.8) | 0.79% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. | |
| Analizada | Alta (8.8) | 0.81% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input. | |
| Analizada | Alta (8.8) | 0.65% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner. | |
| Analizada | Alta (8.8) | 0.68% | — | Langflow | 10/9/2026 | 16/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable… | |
| Analizada | Media (6.5) | 0.35% | — | Langflow | 10/9/2026 | 15/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to… | |
| Analizada | Crítica (9.8) | 0.61% | — | Langflow | 10/9/2026 | 15/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session isolation controls. | |
| Analizada | Crítica (9.8) | 1.1% | — | Flowiseai Flowise | 10/9/2026 | 15/9/2026 | An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint | |
| Aplazada | Media (6.8) | 0.55% | — | AppflowyAI | 10/9/2026 | 10/9/2026 | An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components | |
| Aplazada | Alta (7.1) | 0.39% | — | Appflowy CloudAI | 10/9/2026 | 10/9/2026 | AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to… | |
| Aplazada | Alta (8.6) | 0.47% | — | Lfprojects MlflowAI | 8/9/2026 | 9/9/2026 | Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project. | |
| Analizada | Crítica (9.1) | 0.38% | — | Apache-airflow-providers-fab | 8/9/2026 | 18/9/2026 | Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are fetched from Microsoft's **multi-tenant**… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Lupsonline SEO FlowAI | 5/9/2026 | 8/9/2026 | The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take over the site. Exploitation requires the… | |
| Analizada | Media (6.5) | 0.23% | — | Langflow | 4/9/2026 | 9/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. | |
| Analizada | Alta (7.1) | 0.20% | — | Langflow | 4/9/2026 | 9/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization. | |
| Analizada | Media (6.5) | 0.49% | — | Langflow | 4/9/2026 | 9/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Media (5.4) | 0.29% | — | Langflow | 4/9/2026 | 10/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system. | |
| Analizada | Media (6.5) | 0.34% | — | Langflow | 4/9/2026 | 10/9/2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. | |
| Aplazada | Media (5.1) | 0.23% | — | Roskus Prospero Flow CRMAILaravelAI | 4/9/2026 | 9/9/2026 | Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page. Laravel's VerifyCsrfToken middleware enforces… | |
| Analizada | Alta (7.7) | 0.40% | — | Langflow | 4/9/2026 | 8/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal… | |
| Analizada | Alta (7.5) | 0.29% | — | Langflow | 4/9/2026 | 8/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery. | |
| Analizada | Alta (8.1) | 0.40% | — | Langflow | 4/9/2026 | 10/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. | |
| Analizada | Media (6.5) | 0.49% | — | Langflow | 4/9/2026 | 8/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | |
| Analizada | Media (6.5) | 0.29% | — | Langflow | 4/9/2026 | 8/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. | |
| Analizada | Alta (7.5) | 0.38% | — | Langflow | 4/9/2026 | 8/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields. |