Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 81 respecto a la semana anterior
Críticas / altas1316▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
14.297 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.60% | — | Apache Airflow | 7/7/2026 | 16/9/2026 | Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the same source file. `GET /api/v2/dagSources/{dag_id}` — and the equivalent Dag-source view in the UI — returned the entire source file without redacting Dags the caller was not authorized to read,… | |
| Analizada | Media (6.5) | 0.66% | — | Apache Airflow | 7/7/2026 | 16/9/2026 | The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRETS__BACKEND_KWARG__SECRET_ID` and `AIRFLOW__WORKERS__SECRETS_BACKEND_KWARG__SECRET_ID`) as synthetic config options whose option names were not in `sensitive_config_values`, so the masker did not… | |
| Analizada | Media (4.3) | 0.64% | — | Apache Airflow | 7/7/2026 | 16/9/2026 | A bug in Apache Airflow's `/ui/dependencies` scheduling graph endpoint applied the caller's readable-Dag filter to the top-level serialized Dag key but still emitted referenced Dag IDs through the `dep.source` and `dep.target` fields of trigger / sensor dependency entries. An authenticated UI user with read permission… | |
| Analizada | Media (6.5) | 0.66% | — | Apache Airflow | 7/7/2026 | 16/9/2026 | The Bulk Variables API in Apache Airflow called the redactor without passing the variable's key, so the key-based `should_hide_value_for_key` check (which triggers on secret-suffixed key names like `*_password` / `*_token` / `*_secret`) could not fire for JSON-decodable variable values. An authenticated UI/API user… | |
| Analizada | Crítica (9.8) | 1.6% | — | Apache Airflow | 7/7/2026 | 8/7/2026 | A bug in `BaseSerialization.deserialize()` allowed unrestricted `import_string()` of attacker-controlled class paths when the Scheduler / API Server loaded a serialized DAG: a DAG author could embed a malicious trigger into a DAG to gain remote code execution on the API Server / Scheduler process, crossing the Airflow… | |
| Analizada | Alta (8.6) | 0.45% | — | Kidocode Crawl4ai | 6/7/2026 | 7/7/2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a… | |
| Analizada | Crítica (10) | 0.94% | — | Kidocode Crawl4ai | 6/7/2026 | 8/7/2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote,… | |
| Analizada | Crítica (9.6) | 0.81% | — | Kidocode Crawl4ai | 6/7/2026 | 7/7/2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the… | |
| Pendiente de análisis | Media (6.5) | 0.37% | — | Openai CodexAI | 6/7/2026 | 7/7/2026 | The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing… | |
| Analizada | Alta (7.3) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Corrupción de memoria al procesar múltiples llamadas IOCTL con la misma entrada de descriptor de archivo de búfer. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+44 | 6/7/2026 | 29/9/2026 | Corrupción de memoria al procesar múltiples llamadas IOCTL con la misma entrada de descriptor de archivo de búfer debido al acceso a memoria ya liberada. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Molokai Firmware+56 | 6/7/2026 | 29/9/2026 | Corrupción de memoria cuando se invocan operaciones de control de entrada/salida de dispositivo para mapear y desmapear búferes de memoria persistente debido a una sincronización inadecuada. | |
| Analizada | Alta (8.1) | 0.99% | — | Apache-airflow-providers-google | 6/7/2026 | 8/7/2026 | Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different… | |
| Pendiente de análisis | Alta (7) | 0.15% | — | Suse Rancher AI AgentAI | 6/7/2026 | 6/7/2026 | A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials. | |
| Aplazada | Alta (7.1) | 0.51% | — | Circl AIL FrameworkAI | 5/7/2026 | 6/7/2026 | AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that… | |
| Aplazada | Alta (7.9) | 0.15% | — | Tubitak Bilgem Pardus Domain JoinerAI | 5/7/2026 | 6/7/2026 | Invocation of process using visible sensitive information vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Domain Joiner allows Excavation. This issue affects Pardus Domain Joiner: from 0.5.2 before 0.5.4. | |
| Aplazada | Baja (2.1) | 0.37% | — | Aianytime Awesome-mcp-serverAI | 5/7/2026 | 6/7/2026 | A flaw has been found in AIAnytime Awesome-MCP-Server up to a884bb51bcd99e08e14fd712c749d55d9d9a13ab. Affected by this issue is some unknown functionality of the file mcp-wiki/src/mcp_wiki/server.py of the component mcp-wiki/wiki-summary. This manipulation of the argument url causes server-side request forgery. The… | |
| Aplazada | Baja (1.3) | 0.23% | — | Langchain LanggraphAI | 5/7/2026 | 6/7/2026 | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the file libs/langgraph/langgraph/_internal/_cache.py of the component Task Result Cache. This manipulation of the argument default_cache_key causes use of weak hash. The attack is possible to be… | |
| Aplazada | Baja (1.3) | 0.23% | — | Forceinjection Ai-fundermentalsAI | 4/7/2026 | 6/7/2026 | A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get_conversation_history of the file 08_agentic_system/memory/langchain/code/smart_customer_service.py of the component Memory Recall Handler. The manipulation leads to use of weak hash. Remote… | |
| Analizada | Crítica (9.8) | 0.56% | — | Trailofbits Fickling | 4/7/2026 | 10/7/2026 | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in the shared… | |
| Analizada | Alta (8.8) | 0.59% | — | Trailofbits Fickling | 4/7/2026 | 10/7/2026 | Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for… | |
| Aplazada | Media (5.5) | 0.69% | — | Jairiidriss Restaurant-website-php-mysqlAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried… | |
| Aplazada | Baja (1.3) | 0.36% | — | Federatedai FateAI | 4/7/2026 | 6/7/2026 | A vulnerability has been found in FederatedAI FATE up to 2.2.0. This affects the function QueuePushReqStreamObserver.initEggroll of the file java/osx/osx-broker/src/main/java/org/fedai/osx/broker/grpc/QueuePushReqStreamObserver.java of the component OSX Broker. Such manipulation of the argument… | |
| Aplazada | Alta (7.6) | 0.46% | — | Mmaitre314 PicklescanAI | 4/7/2026 | 5/10/2026 | picklescan anterior a 0.0.34 falla en detectar la función incorporada _operator.methodcaller al escanear archivos pickle en busca de código malicioso. Los atacantes pueden crear cargas útiles pickle maliciosas utilizando _operator.methodcaller que evaden la detección y ejecutan código arbitrario cuando son cargadas… | |
| Aplazada | Alta (7.6) | 0.56% | — | Mmaitre314 PicklescanAI | 4/7/2026 | 5/10/2026 | picklescan anterior a 0.0.33 no detecta las llamadas a la función operator.methodcaller en archivos pickle, permitiendo a los atacantes eludir las comprobaciones de seguridad. Atacantes remotos pueden crear cargas útiles pickle maliciosas utilizando operator.methodcaller que ejecutan código arbitrario cuando se… |