Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▲ 220 respecto a la semana anterior
Críticas / altas1330▼ 101 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

14.299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.45%—Mmaitre314 PicklescanAI24/6/20265/10/2026
picklescan anterior a la 0.0.29 no detecta archivos pickle maliciosos que explotan la función idlelib.debugobj.ObjectTreeItem.SetText en métodos reduce. Los atacantes pueden crear archivos pickle con código incrustado que elude la detección de picklescan y ejecuta comandos arbitrarios cuando se llama a pickle.load().
AnalizadaAlta (8.5)0.52%—Flowiseai Flowise24/6/202630/9/2026
Flowise hasta la versión 2.2.7 contiene una vulnerabilidad de inyección SQL en la API importChatflows. Debido a una validación insuficiente del valor chatflow.id, un usuario autenticado puede proporcionar un archivo de importación JSON manipulado cuyo campo id se concatena sin sanear en una cláusula SQL IN,…
AplazadaMedia (5.4)0.23%—AI Share AND SummarizeAI24/6/202625/6/2026
The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.
AplazadaAlta (7.2)0.36%—Email Javascript CloakAI24/6/202625/6/2026
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.8)0.20%—Rtk-ai RTKAI23/6/202625/6/2026
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several shell constructs that Bash treats as command execution boundaries or nested execution. As a result, a command beginning with an allowed prefix such as…
AnalizadaMedia (6.9)0.11%—Rtk-ai RTK23/6/20261/7/2026
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration files. RTK automatically loads .rtk/filters.toml from the working directory with highest priority and without user notification. An attacker can place a…
AnalizadaAlta (8.8)0.55%—Rtkai Rtk-rewrite23/6/20261/7/2026
@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewrite OpenClaw plugin passes attacker-controlled input directly into a shell-backed execSync() template string without shell-safe escaping. JSON.stringify() wraps the value…
AnalizadaAlta (7.5)1.6%💥 ExploitKidocode Crawl4ai23/6/202629/6/2026
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through it, reaching internal…
AnalizadaAlta (7.5)0.43%—Kidocode Crawl4ai23/6/202629/6/2026
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker could reach internal services…
AnalizadaCrítica (10)2.9%💥 ExploitKidocode Crawl4ai23/6/202629/6/2026
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only blocks attributes starting with underscore. Python generator and frame object attributes (gi_frame, f_back, f_builtins) do NOT start with…
AplazadaNinguna (0)0.39%—Userlog-details.phpAI23/6/202625/6/2026
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would have any malicious JavaScript payload…
AplazadaCrítica (9.3)1.1%—Mmaitre314 PicklescanAI23/6/202623/6/2026
picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files importing these unblocked modules to…
AnalizadaMedia (6)0.32%—Flowiseai Flowise23/6/202625/6/2026
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate…
AnalizadaAlta (8.7)7.5%💥 ExploitFlowiseai Flowise23/6/202625/6/2026
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can…
AnalizadaMedia (5.3)0.34%—Kidocode Crawl4ai23/6/202625/6/2026
Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl URLs and error messages via innerHTML without escaping. An attacker can submit a crafted crawl request with malicious markup that executes in an operator's browser when viewing the dashboard.
AnalizadaCrítica (9.2)0.91%—Kidocode Crawl4ai23/6/202625/6/2026
Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. Remote attackers can exploit insufficient…
AplazadaAlta (7.6)0.38%—Python IdlelibAIMmaitre314 PicklescanAI23/6/20265/10/2026
picklescan anterior a 0.0.29 no detecta archivos pickle maliciosos utilizando idlelib.autocomplete.AutoComplete.fetch_completions en métodos reduce. Los atacantes pueden incrustar código no detectado en archivos pickle que ejecuta comandos arbitrarios cuando son cargados por las víctimas.
AplazadaAlta (7.6)0.48%—Pytorch TorchAIMmaitre314 PicklescanAI23/6/20265/10/2026
picklescan anterior a 0.0.28 no logra detectar llamadas maliciosas a la función torch.jit.unsupported_tensor_ops.execWrapper incrustadas en archivos pickle. Los atacantes pueden elaborar archivos pickle maliciosos que eluden la detección de picklescan y ejecutan código arbitrario cuando se cargan mediante…
AplazadaAlta (7.6)0.38%—Numpy F2pyAIMmaitre314 PicklescanAI23/6/20265/10/2026
picklescan anterior a 0.0.33 no logra detectar archivos pickle maliciosos que invocan la función numpy.f2py.crackfortran.myeval a través del método reduce. Atacantes pueden elaborar archivos pickle maliciosos incrustando código arbitrario que evade la detección de picklescan y ejecuta código remoto cuando se carga.
AplazadaAlta (7.6)0.58%—Mmaitre314 PicklescanAI23/6/20265/10/2026
picklescan anterior a la versión 0.0.29 no detecta la función profile.Profile.runctx al analizar archivos pickle, lo que permite a los atacantes incrustar código malicioso no detectado. Atacantes remotos pueden crear archivos pickle maliciosos utilizando profile.Profile.runctx en el método reduce para lograr ejecución…
AnalizadaAlta (8.7)0.42%—Flowiseai Flowise23/6/202630/9/2026
Flowise anterior a la versión 3.0.10 (versiones afectadas 3.0.7 y anteriores) contiene una vulnerabilidad de cambio de correo electrónico no verificado. Un usuario autenticado puede cambiar la dirección de correo electrónico de la cuenta, utilizada como identificador de inicio de sesión y canal de recuperación de…
AnalizadaAlta (8.7)0.77%—TraefikGolang GORedhat Openshift AI23/6/202626/9/2026
Traefik anterior a 2.10.5 y 3.0.0-beta4 está afectado por una vulnerabilidad de denegación de servicio en el manejo de solicitudes HTTP/2 heredada de la implementación de HTTP/2 de la biblioteca estándar de Go (CVE-2023-44487 / CVE-2023-39325, la técnica 'Rapid Reset'). Un atacante remoto puede crear y cancelar…
ModificadaMedia (6.5)0.60%—Openbsd OpensshRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux23/6/20267/10/2026
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters.…
AnalizadaMedia (5.3)0.39%—Flowiseai Flowise22/6/202625/6/2026
Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default), the endpoint returns not only the chatflows bound to the supplied API key but also all chatflows across every workspace that have no API key…
AnalizadaCrítica (9.2)0.48%—Kidocode Crawl4ai22/6/202630/6/2026
Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm endpoints that fetch arbitrary user-supplied URLs without validation. Unauthenticated attackers can bypass the internal-address blocklist using IPv6-mapped IPv4 addresses to reach internal services…