Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.35% | — | Checkview Automated TestingAI | 25/6/2026 | 29/6/2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. | |
| Aplazada | Alta (7.7) | 0.53% | — | AutogptAI | 24/6/2026 | 25/6/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.52, the Fill Text Template block is vulnerable to a Denial of Service (DoS) attack. While the backend implements a SandboxedEnvironment to prevent unauthorized attribute… | |
| Analizada | Crítica (9.6) | 0.70% | — | Autodesk Fusion | 22/6/2026 | 24/6/2026 | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. | |
| Aplazada | Alta (8.8) | 0.32% | — | AutogptAI | 18/6/2026 | 18/6/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), which is passed to… | |
| Aplazada | Alta (8.7) | 0.34% | — | AutogptAI | 18/6/2026 | 29/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `MediaDurationBlock` will download and store the video in a temporary directory without deleting before all noded are done. `StepThroughItemsBlock` can be used to iterate… | |
| Aplazada | Alta (7.1) | 0.31% | — | AutogptAI | 18/6/2026 | 29/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `AddAudioToVideoBlock` will download and store the video and audio in a temporary directory without deleting before all noded are done. `StepThroughItemsBlock` can be used to… | |
| Aplazada | Alta (8.7) | 0.34% | — | AutogptAI | 18/6/2026 | 29/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, ScreenshotWebPageBlock will store the captured screenshots in a temporary directory. `StepThroughItemsBlock` can be used to iterate `ScreenshotWebPageBlock` multiple times.… | |
| Aplazada | Alta (8.7) | 0.34% | — | AutogptAI | 18/6/2026 | 29/9/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, `StepThroughItemsBlock` can iterate all the contents in a list and send them to `FileStoreBlock` for downloading one by one. Although `FileStoreBlock` has access time limits for… | |
| Aplazada | Alta (8.7) | 0.43% | — | AutogptAI | 18/6/2026 | 6/10/2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.63, AutoGPT's LoopVideoBLock allows users to input a video file and process the video, such as looping it 5 times or extending the time, and finally writing it to disk. However, there… | |
| Aplazada | Media (6.9) | 0.28% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 17/6/2026 | 18/6/2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack… | |
| Analizada | Media (5.5) | 0.12% | — | Autodesk Revit | 17/6/2026 | 29/6/2026 | A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition. | |
| Aplazada | Alta (8.1) | 0.36% | — | AutopartsAI | 17/6/2026 | 17/6/2026 | Unauthenticated Local File Inclusion in AutoParts <= 1.5.8 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Auto RepairAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Auto Repair <= 22.6 versions. | |
| Pendiente de análisis | Media (6.3) | 0.45% | — | Rockwellautomation CompactlogixAI | 16/6/2026 | 17/6/2026 | A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct… | |
| Pendiente de análisis | Alta (8.8) | 0.43% | — | Rockwellautomation 1794-aentrAI | 16/6/2026 | 17/6/2026 | An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If… | |
| Pendiente de análisis | Crítica (9.2) | 0.29% | — | Rockwellautomation Factorytalk Historian Site EditionAI | 16/6/2026 | 7/10/2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. | |
| Aplazada | Alta (8.5) | 0.36% | — | Swit WP Sessions Time Monitoring Full AutomaticAI | 16/6/2026 | 17/6/2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | AutomatorwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions. | |
| Aplazada | Alta (7.2) | 0.28% | — | AutomatorwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | AutomatrwpAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Authentication in AutomatorWP <= 5.6.7 versions. | |
| Aplazada | Alta (7.1) | 0.40% | — | Funnelkit AutomationsAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions. | |
| Aplazada | Baja (2.1) | 0.27% | — | Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI | 14/6/2026 | 23/7/2026 | A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has… | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject… | |
| Modificada | Alta (7.8) | 0.23% | — | Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux | 13/6/2026 | 21/9/2026 | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the… | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… |