Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.56% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 14/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft… | |
| Aplazada | Media (5.3) | 0.52% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 15/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.8) | 0.45% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Uncanny Automator PROAI | 7/7/2026 | 7/7/2026 | The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites… | |
| Analizada | Alta (8.8) | 0.11% | — | Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+124 | 6/7/2026 | 7/7/2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | |
| Aplazada | Alta (8.4) | 0.16% | — | BR Industrial Automation AprolAI | 6/7/2026 | 6/7/2026 | Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. | |
| Aplazada | Crítica (9.1) | 0.22% | — | B AND R Industrial Automation Gmbh AprolAI | 6/7/2026 | 6/7/2026 | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. | |
| Aplazada | Baja (2.9) | 0.40% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 3/7/2026 | 6/7/2026 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 3/7/2026 | 7/7/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote… | |
| Aplazada | Media (6.9) | 0.51% | — | AutobangumiAI | 2/7/2026 | 14/7/2026 | AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during… | |
| Aplazada | Crítica (9.3) | 0.80% | — | AutobingumiAI | 2/7/2026 | 14/7/2026 | AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can… | |
| Aplazada | Alta (7.1) | 0.25% | — | Automotive CAR Dealership BusinessAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Automotive ListingsAI | 2/7/2026 | 2/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions. | |
| Analizada | Crítica (9.1) | 0.41% | — | IBM Business Automation Manager | 30/6/2026 | 2/7/2026 | IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Media (6.5) | 0.33% | — | IBM Devops AutomationIBM Devops Loop | 30/6/2026 | 6/10/2026 | IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Alta (7.5) | 0.66% | — | Mz-automation Lib60870AI | 29/6/2026 | 4/8/2026 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Aplazada | Media (5.4) | 0.25% | — | AutogptAI | 26/6/2026 | 26/6/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the webhook belongs to the authenticated user.… | |
| Aplazada | Alta (8.5) | 0.37% | — | AutogptAI | 26/6/2026 | 26/6/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services. _is_ip_blocked() in backend/backend/util/request.py… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Uncanny Automator PROAI | 26/6/2026 | 26/6/2026 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Valvepress AutomaticAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions. | |
| Aplazada | Alta (8.1) | 0.44% | — | Uncannyowl Uncanny AutomatorAI | 26/6/2026 | 26/6/2026 | Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions. | |
| Aplazada | Media (5.3) | 0.31% | — | AutogptAI | 26/6/2026 | 29/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will… | |
| Aplazada | Media (5.3) | 0.38% | — | AutogptAI | 26/6/2026 | 29/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will consume 50G… | |
| Aplazada | Alta (8.4) | 0.18% | — | Hornerautomation CscapeAI | 25/6/2026 | 25/6/2026 | Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. |