Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

4530 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.35%—Checkview Automated TestingAI25/6/202629/6/2026
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
AplazadaAlta (7.7)0.53%—AutogptAI24/6/202625/6/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While the backend implements a SandboxedEnvironment to prevent unauthorized attribute…
AnalizadaCrítica (9.6)0.70%—Autodesk Fusion22/6/202624/6/2026
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.
AplazadaAlta (8.8)0.32%—AutogptAI18/6/202618/6/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to…
AplazadaAlta (8.7)0.34%—AutogptAI18/6/202629/9/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `MediaDurationBlock` will download and store the video in a temporary directory without deleting before all noded are done. `StepThroughItemsBlock` can be used to iterate…
AplazadaAlta (7.1)0.31%—AutogptAI18/6/202629/9/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `AddAudioToVideoBlock` will download and store the video and audio in a temporary directory without deleting before all noded are done. `StepThroughItemsBlock` can be used to…
AplazadaAlta (8.7)0.34%—AutogptAI18/6/202629/9/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, ScreenshotWebPageBlock will store the captured screenshots in a temporary directory. `StepThroughItemsBlock` can be used to iterate `ScreenshotWebPageBlock` multiple times.…
AplazadaAlta (8.7)0.34%—AutogptAI18/6/202629/9/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThroughItemsBlock` can iterate all the contents in a list and send them to `FileStoreBlock` for downloading one by one. Although `FileStoreBlock` has access time limits for…
AplazadaAlta (8.7)0.43%—AutogptAI18/6/20266/10/2026
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's LoopVideoBLock allows users to input a video file and process the video, such as looping it 5 times or extending the time, and finally writing it to disk. However, there…
AplazadaMedia (6.9)0.28%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI17/6/202618/6/2026
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack…
AnalizadaMedia (5.5)0.12%—Autodesk Revit17/6/202629/6/2026
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
AplazadaAlta (8.1)0.36%—AutopartsAI17/6/202617/6/2026
Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions.
AplazadaAlta (7.1)0.24%—Auto RepairAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions.
Pendiente de análisisMedia (6.3)0.45%—Rockwellautomation CompactlogixAI16/6/202617/6/2026
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct…
Pendiente de análisisAlta (8.8)0.43%—Rockwellautomation 1794-aentrAI16/6/202617/6/2026
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If…
Pendiente de análisisCrítica (9.2)0.29%—Rockwellautomation Factorytalk Historian Site EditionAI16/6/20267/10/2026
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
AplazadaAlta (8.5)0.36%—Swit WP Sessions Time Monitoring Full AutomaticAI16/6/202617/6/2026
Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.
AplazadaAlta (7.1)0.25%—AutomatorwpAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.
AplazadaAlta (7.2)0.28%—AutomatorwpAI15/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
AplazadaAlta (7.1)0.40%—AutomatrwpAI15/6/202617/6/2026
Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions.
AplazadaAlta (7.1)0.40%—Funnelkit AutomationsAI15/6/202617/6/2026
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
AplazadaBaja (2.1)0.27%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI14/6/202623/7/2026
A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has…
ModificadaMedia (5.5)0.19%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject…
ModificadaAlta (7.8)0.23%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the…
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…