Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

14.307 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.11%—F5 Big-ip Domain Name System13/5/202629/6/2026
When BIG-IP DNS is provisioned, a vulnerability exists in the gtm_add and bigip_add iControl REST commands that return the ssh-password parameter in cleartext in the iControl REST response and is also logged in the audit log. This may allow a highly privileged, authenticated attacker with access to the audit log to…
AnalizadaMedia (6.9)0.89%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202629/6/2026
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have reached End of Technical Support (EoTS) are…
AplazadaMedia (5.1)0.24%—Powie Whois Domain CheckAI13/5/202617/6/2026
Powie's WHOIS Domain Check 0.9.31 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary JavaScript by exploiting unsanitized input fields in plugin settings. Attackers can submit malicious payloads through textarea and input elements in the pwhois_settings.php…
AplazadaCrítica (9.3)0.73%—Guardianwall MailsuiteAIGuardianwall Mail Security CloudAI13/5/202617/6/2026
Stack-based buffer overflow vulnerability exists in GUARDIANWALL MailSuite and GUARDIANWALL Mail Security Cloud (SaaS version). If a remote attacker sends a specially crafted request to the product's web service, arbitrary code may be executed when the product is configured to run pop3wallpasswd with grdnwww user…
AnalizadaAlta (7.8)0.26%—Adobe Substance 3D Painter12/5/202628/8/2026
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AnalizadaAlta (7.8)0.26%—Adobe Substance 3D Painter12/5/202628/8/2026
Substance3D - Painter versions 12.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
AplazadaCrítica (9.8)0.93%—Guardrailsai GuardrailsAI12/5/202617/6/2026
Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install, the system retrieves a manifest from the Guardrails Hub and dynamically executes a script specified in the post_install field. The script…
AplazadaAlta (8.4)0.22%—Juno Network JunoclawfastaioAIJuno Network Plugin ShellAI12/5/202617/6/2026
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped every agent-supplied command in 'sh -c' / 'cmd /C' and passed the full argument string to the shell's parser, allowing shell metacharacters in agent-supplied arguments to be interpreted as command…
Pendiente de análisisMedia (5.4)0.09%—Electronhub AI PlaygroundAI12/5/202617/6/2026
Uncontrolled search path for some AI Playground software before version 3.0.0 alpha within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially…
AnalizadaAlta (7.2)0.36%—Fortinet Fortimail12/5/20267/10/2026
Una neutralización inadecuada de elementos especiales utilizados en un comando SQL (vulnerabilidad de 'inyección SQL&') vulnerabilidad [CWE-89] vulnerabilidad en Fortinet FortiMail 7.6.0 a 7.6.3, FortiMail 7.4.0 a 7.4.5, FortiMail 7.2.0 a 7.2.8 permite a un atacante privilegiado autenticado ejecutar código o comandos…
ModificadaAlta (7.8)0.55%—Lightningai Pytorch Lightning12/5/202617/6/2026
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive…
AnalizadaAlta (8.2)0.35%—Vmware Spring AI12/5/202617/6/2026
A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an unintended way. Applications using the affected advisor with user-controlled input may be susceptible to manipulation of model behavior across conversation turns.
AnalizadaAlta (7.5)0.41%—Vmware Spring AI12/5/202617/6/2026
Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in unintended data exposure between users.
AplazadaAlta (7.5)0.69%—Aiwu AI Chatbot Workflow AutomationAI12/5/202617/6/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This makes it possible for…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaCrítica (9.3)0.50%—Thinkinai DeepchatAI11/5/202617/6/2026
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepancy between the backend validation layer and the frontend browser rendering engine. The SVGSanitizer…
AplazadaCrítica (9.6)0.56%—Thinkinai DeepchatAI11/5/202617/6/2026
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerable to an arbitrary protocol execution bypass (RCE). While the patch correctly restricted api.openExternal() inside the…
AplazadaMedia (5.5)0.64%—Aiwaves-cn AgentsAIAiwaves-cn Cheshire CAT CoreAI11/5/202617/6/2026
A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/cat/looking_glass/stray_cat.py of the component cheshire_cat_core. This manipulation causes resource consumption. Remote…
AplazadaMedia (5.5)0.64%—Vectifyai PageindexAI11/5/202617/6/2026
A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the function toc_transformer of the file pageindex/page_index.py of the component PDF Table of Contents Handler. The manipulation results in infinite loop. The attack may be…
AnalizadaAlta (7.5)0.34%—Jetbrains Teamcity11/5/202617/6/2026
In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
AnalizadaMedia (5.3)0.48%—Flowiseai Flowise11/5/202617/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) instead of using the secured wrapper. These tools include (1) OpenAPIToolkit/OpenAPIToolkit.ts, (2)…
AplazadaAlta (8.7)0.54%—Network-aiAI11/5/202617/6/2026
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no authentication, session, origin, or token check, and dispatches them directly to the orchestrator's tool registry. The default bind address is 0.0.0.0. As a result, any party…
AplazadaMedia (5.7)0.39%—Taiga FrontAI11/5/202617/6/2026
Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.
AnalizadaMedia (5.3)0.31%—Torchbox Wagtail11/5/202617/6/2026
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and Images API incorrectly listed items in private collections. A user with access to the API could see the filename and name of documents and images in private collections. This vulnerability is fixed in…
AnalizadaMedia (6.5)0.34%—Torchbox Wagtail11/5/202617/6/2026
Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with limited access to pages could copy a page they don't have access to to an area of the site they do. Once coped, they'd be able to view its contents, and potentially publish it. Permissions were…