Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5399 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.39%—Appflowy CloudAI10/9/202610/9/2026
AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published views with attacker-controlled title, body and metadata into victim workspaces to…
AplazadaMedia (5.6)0.25%—Simple Cloudflare TurnstileAI10/9/202610/9/2026
Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.
AplazadaMedia (6.5)0.28%—Cloudflare TurnstileAI10/9/202610/9/2026
Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.
Pendiente de análisisBaja (2.4)0.19%—Paloaltonetworks Checkov BY Prisma CloudAI10/9/202610/9/2026
A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.
Pendiente de análisisBaja (1.1)0.82%—Paloaltonetworks Checkov BY Prisma CloudAI10/9/202610/9/2026
An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.
AplazadaMedia (4.3)0.42%—Ruoyi-cloud-plusAI9/9/202614/9/2026
In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission annotations, and the Service layer does not verify whether the current user is the task handler/related user. Authenticated low-privileged remote attackers can read sensitive workflow task details…
Pendiente de análisisCrítica (10)0.74%—Google Cloud Agent Development KITAIPythonAI9/9/20269/9/2026
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay.
AplazadaMedia (6.9)0.61%—Ragic Enterprise Cloud DatabaseAI9/9/20269/9/2026
The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.
Pendiente de análisisMedia (5.1)0.10%—Samsung Cloud AssistantAI9/9/202610/9/2026
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.
Pendiente de análisisCrítica (9.9)0.39%—Fortinet FortisandboxAIFortinet Fortisandbox CloudAIFortinet Fortisandbox PaasAI8/9/20268/9/2026
A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.
AnalizadaMedia (6.5)0.58%—Microsoft Azure Cyclecloud8/9/202629/9/2026
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
AnalizadaAlta (8.1)0.69%—Microsoft Spring Cloud8/9/202629/9/2026
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
AplazadaMedia (6.5)0.27%—Onlyoffice Ownclouds IntegrationAIOwncloudsAI8/9/202610/9/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can…
AplazadaBaja (2.1)0.51%—Modelcloud GptqmodelAI7/9/20268/9/2026
A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file gptqmodel/nn_modules/qlinear/tritonv2.py of the component Triton dequantization kernel. Such manipulation of the argument g_idx leads to out-of-bounds read. The attack can be executed remotely. The…
Pendiente de análisisMedia (5.3)0.23%—IBM Cloud PAK FOR Data SystemAI4/9/20268/9/2026
IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
AplazadaMedia (6)0.40%—Appflowy CloudAI4/9/202610/9/2026
AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages with victim object identifiers to read…
AplazadaAlta (7.7)0.57%—Appflowy-cloudAI4/9/202610/9/2026
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete…
Pendiente de análisisAlta (8.7)0.67%—Google Cloud Agent Development KITAI4/9/20268/9/2026
A Path Traversal vulnerability in the builder endpoint in Google Cloud Agent Development Kit (ADK) versions 1.9.0 through 1.21.0 on Python allows an unauthenticated remote attacker to read arbitrary files using a crafted file_path query parameter.
Pendiente de análisisAlta (8.5)0.35%—Google Cloud Integration ConnectorsAI4/9/20268/9/2026
A Missing Authorization vulnerability in HTTP Connector in Google Cloud Integration Connectors versions prior to 2025-12-11 on Google Cloud Platform allows an authenticated user to escalate privileges and take over a Google Cloud Project using unauthorized service account attachment. This vulnerability was patched on…
AnalizadaMedia (5.4)0.15%—Elastic Cloud ON Kubernetes2/9/20264/9/2026
Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate material to be included in the Elasticsearch…
AnalizadaBaja (3.5)0.28%—Elastic Cloud ON Kubernetes2/9/20263/9/2026
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to retain unauthorized read access to the…
Pendiente de análisisCrítica (9.4)0.14%—Google Cloud BuildAI31/8/202631/8/2026
An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched on 24 June 2026, and no customer action is…
AplazadaAlta (8.7)0.94%—Ajcloud AJY IPCAI30/8/202610/9/2026
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests…
AplazadaAlta (8.8)0.64%—Kubeedge CloudcoreAI29/8/202624/9/2026
KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling.
AplazadaCrítica (9.3)0.90%—Cloud CommanderAI29/8/202624/9/2026
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.