Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5399 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.39% | — | Appflowy CloudAI | 10/9/2026 | 10/9/2026 | AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to… | |
| Aplazada | Media (5.6) | 0.25% | — | Simple Cloudflare TurnstileAI | 10/9/2026 | 10/9/2026 | Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. | |
| Aplazada | Media (6.5) | 0.28% | — | Cloudflare TurnstileAI | 10/9/2026 | 10/9/2026 | Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions. | |
| Pendiente de análisis | Baja (2.4) | 0.19% | — | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file. | |
| Pendiente de análisis | Baja (1.1) | 0.82% | — | Paloaltonetworks Checkov BY Prisma CloudAI | 10/9/2026 | 10/9/2026 | An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov. | |
| Aplazada | Media (4.3) | 0.42% | — | Ruoyi-cloud-plusAI | 9/9/2026 | 14/9/2026 | In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details… | |
| Pendiente de análisis | Crítica (10) | 0.74% | — | Google Cloud Agent Development KITAIPythonAI | 9/9/2026 | 9/9/2026 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Aplazada | Media (6.9) | 0.61% | — | Ragic Enterprise Cloud DatabaseAI | 9/9/2026 | 9/9/2026 | The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files. | |
| Pendiente de análisis | Media (5.1) | 0.10% | — | Samsung Cloud AssistantAI | 9/9/2026 | 10/9/2026 | Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings. | |
| Pendiente de análisis | Crítica (9.9) | 0.39% | — | Fortinet FortisandboxAIFortinet Fortisandbox CloudAIFortinet Fortisandbox PaasAI | 8/9/2026 | 8/9/2026 | A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests. | |
| Analizada | Media (6.5) | 0.58% | — | Microsoft Azure Cyclecloud | 8/9/2026 | 29/9/2026 | Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network. | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Spring Cloud | 8/9/2026 | 29/9/2026 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.5) | 0.27% | — | Onlyoffice Ownclouds IntegrationAIOwncloudsAI | 8/9/2026 | 10/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can… | |
| Aplazada | Baja (2.1) | 0.51% | — | Modelcloud GptqmodelAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The… | |
| Pendiente de análisis | Media (5.3) | 0.23% | — | IBM Cloud PAK FOR Data SystemAI | 4/9/2026 | 8/9/2026 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Aplazada | Media (6) | 0.40% | — | Appflowy CloudAI | 4/9/2026 | 10/9/2026 | AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages with victim object identifiers to read… | |
| Aplazada | Alta (7.7) | 0.57% | — | Appflowy-cloudAI | 4/9/2026 | 10/9/2026 | AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete… | |
| Pendiente de análisis | Alta (8.7) | 0.67% | — | Google Cloud Agent Development KITAI | 4/9/2026 | 8/9/2026 | A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter. | |
| Pendiente de análisis | Alta (8.5) | 0.35% | — | Google Cloud Integration ConnectorsAI | 4/9/2026 | 8/9/2026 | A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on… | |
| Analizada | Media (5.4) | 0.15% | — | Elastic Cloud ON Kubernetes | 2/9/2026 | 4/9/2026 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch… | |
| Analizada | Baja (3.5) | 0.28% | — | Elastic Cloud ON Kubernetes | 2/9/2026 | 3/9/2026 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the… | |
| Pendiente de análisis | Crítica (9.4) | 0.14% | — | Google Cloud BuildAI | 31/8/2026 | 31/8/2026 | An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is… | |
| Aplazada | Alta (8.7) | 0.94% | — | Ajcloud AJY IPCAI | 30/8/2026 | 10/9/2026 | AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests… | |
| Aplazada | Alta (8.8) | 0.64% | — | Kubeedge CloudcoreAI | 29/8/2026 | 24/9/2026 | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling. | |
| Aplazada | Crítica (9.3) | 0.90% | — | Cloud CommanderAI | 29/8/2026 | 24/9/2026 | Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory. |