Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
23.893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.51% | — | A2ui-project A2uiAI | 16/9/2026 | 16/9/2026 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileResolver. The manipulation leads to server-side request forgery. It is possible to… | |
| Aplazada | Media (5.1) | 0.32% | — | A2ui-project A2uiAI | 16/9/2026 | 16/9/2026 | A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argument primaryColor results in injection. The attack is possible to be carried out… | |
| Aplazada | Media (5.1) | 0.35% | — | A2ui-project A2uiAI | 16/9/2026 | 22/9/2026 | A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-chat-canvas. Executing a manipulation can lead to cross site scripting. The attack… | |
| Aplazada | Media (6.9) | 0.72% | — | A2ui-project A2uiAI | 15/9/2026 | 16/9/2026 | A vulnerability was identified in a2ui-project a2ui up to 0.10.6. Affected is an unknown function of the file renderers/web_core/src/v0_9/basic_catalog/functions/safe_regex.ts of the component Basic Catalog. Such manipulation leads to inefficient regular expression complexity. The attack can be launched remotely. | |
| Aplazada | Alta (7.1) | 0.28% | — | Oracle Project IntelligenceAIOracle E-business SuiteAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… | |
| Aplazada | Alta (8.1) | 0.35% | — | Oracle Project IntelligenceAIOracle E-business SuiteAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… | |
| Pendiente de análisis | Media (4.8) | 0.15% | — | Lfprojects ApptainerAI | 15/9/2026 | 25/9/2026 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also authorizes a sibling path such as /data/safe-but-unsafe. A local user can consequently… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Record Management SystemAI | 15/9/2026 | 22/9/2026 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (1.2) | 0.38% | — | Openbankproject Obp-apiAI | 15/9/2026 | 16/9/2026 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be launched remotely. A high complexity level is… | |
| Aplazada | Crítica (9.1) | 0.46% | — | MotioneyeAIMotion Project MotionAI | 15/9/2026 | 30/9/2026 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authentication material without server-side session validation. An… | |
| Aplazada | Baja (2.1) | 0.53% | — | Vllm-project VllmAI | 15/9/2026 | 15/9/2026 | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource consumption. The attack can be initiated remotely. The exploit has been publicly… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 15/9/2026 | A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be… | |
| Aplazada | Media (5.5) | 0.41% | — | Sourcecodester Katojkalemba Online Food Ordering SystemAI | 15/9/2026 | 16/9/2026 | A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released… | |
| Aplazada | Media (5.3) | 0.39% | — | A2aproject A2a-javaAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing… | |
| Aplazada | Media (6.9) | 0.66% | — | A2aproject A2a-javaAI | 14/9/2026 | 15/9/2026 | A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation… | |
| Pendiente de análisis | Alta (7.1) | 0.10% | — | PackagekitAIFedoraproject Dnf5AI | 14/9/2026 | 18/9/2026 | A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is… | |
| Pendiente de análisis | Media (4.6) | 0.17% | — | Zephyrproject ZephyrAI | 14/9/2026 | 14/9/2026 | The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_size is decoded directly from the SDIO card's CIS FUNCE tuple in sdio_decode_cis()… | |
| Aplazada | Alta (7.5) | 0.63% | — | Palletsprojects FlaskAIJugmac00 Flask-reuploadedAI | 14/9/2026 | 30/9/2026 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept… | |
| Aplazada | Media (5.3) | 0.37% | — | A2aproject A2a-pythonAI | 14/9/2026 | 15/9/2026 | A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request… | |
| Analizada | Media (5.5) | 0.16% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/9/2026 | 7/10/2026 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability… | |
| Aplazada | Baja (1.9) | 0.16% | — | Vllm-project VllmAI | 14/9/2026 | 15/9/2026 | A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The attack is only possible with local access.… | |
| Aplazada | Baja (2.1) | 0.39% | — | Jaygajera17 E-commerce-project-springbootAI | 13/9/2026 | 16/9/2026 | A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to… | |
| Pendiente de análisis | Media (4.8) | 0.17% | 💥 PoC | Alsa-project Alsa LIBAI | 13/9/2026 | 24/9/2026 | alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments… | |
| Pendiente de análisis | Alta (8.4) | 0.23% | — | ProjenAI | 11/9/2026 | 11/9/2026 | Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters in project configuration values and… | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | ProjenAI | 11/9/2026 | 11/9/2026 | Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted entries in the version-controlled… |