Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

4530 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.56%—Aiwu AI Chatbot Workflow AutomationAI11/7/202614/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft…
AplazadaMedia (5.3)0.52%—Aiwu AI Chatbot Workflow AutomationAI11/7/202615/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's…
AplazadaCrítica (9.8)0.48%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaAlta (8.8)0.45%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaCrítica (9.8)0.55%—Uncanny Automator PROAI7/7/20267/7/2026
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites…
AnalizadaAlta (8.8)0.11%—Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+1246/7/20267/7/2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
AplazadaAlta (8.4)0.16%—BR Industrial Automation AprolAI6/7/20266/7/2026
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
AplazadaCrítica (9.1)0.22%—B AND R Industrial Automation Gmbh AprolAI6/7/20266/7/2026
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
AplazadaBaja (2.9)0.40%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20266/7/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as…
AplazadaBaja (2.1)0.37%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI3/7/20267/7/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote…
AplazadaMedia (6.9)0.51%—AutobangumiAI2/7/202614/7/2026
AutoBangumi before 3.2.8 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to probe internal network services by supplying arbitrary host values to an unprotected setup endpoint. Attackers can send requests to the POST /api/v1/setup/test-downloader endpoint during…
AplazadaCrítica (9.3)0.80%—AutobingumiAI2/7/202614/7/2026
AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the administrator by using the publicly known default credentials seeded at startup via add_default_user() in the database user module when the users table is empty. Attackers can…
AplazadaAlta (7.1)0.25%—Automotive CAR Dealership BusinessAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Automotive Car Dealership Business <= 13.3.3 versions.
AplazadaAlta (7.1)0.25%—Automotive ListingsAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Automotive Listings <= 18.6 versions.
AnalizadaCrítica (9.1)0.41%—IBM Business Automation Manager30/6/20262/7/2026
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaMedia (6.5)0.33%—IBM Devops AutomationIBM Devops Loop30/6/20266/10/2026
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
AplazadaAlta (7.5)0.66%—Mz-automation Lib60870AI29/6/20264/8/2026
A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.
AplazadaMedia (5.4)0.25%—AutogptAI26/6/202626/6/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/integrations/webhooks/{webhook_id}/ping` endpoint fetches the target webhook by primary key alone without verifying that the webhook belongs to the authenticated user.…
AplazadaAlta (8.5)0.37%—AutogptAI26/6/202626/6/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services. _is_ip_blocked() in backend/backend/util/request.py…
AplazadaCrítica (9.8)0.56%—Uncanny Automator PROAI26/6/202626/6/2026
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
AplazadaAlta (7.1)0.25%—Valvepress AutomaticAI26/6/202626/6/2026
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
AplazadaAlta (8.1)0.44%—Uncannyowl Uncanny AutomatorAI26/6/202626/6/2026
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
AplazadaMedia (5.3)0.31%—AutogptAI26/6/202629/9/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in ExtractTextInformationBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will…
AplazadaMedia (5.3)0.38%—AutogptAI26/6/202629/9/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is a DoS vulnerability in AITextSummarizerBlock. Malicious users can amplify their input. For example, if a malicious user inputs 10K of content, the server will consume 50G…
AplazadaAlta (8.4)0.18%—Hornerautomation CscapeAI25/6/202625/6/2026
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.