Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.39% | 💥 PoC | Infiniflow RagflowAI | 18/8/2026 | 16/9/2026 | RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without… | |
| Aplazada | Media (6.5) | 0.45% | — | DeskflowAI | 17/8/2026 | 9/9/2026 | Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messages to ClipboardChunk::assemble() in src/lib/deskflow/ClipboardChunk.cpp, causing the server path in src/lib/server/ClientProxy1_6.cpp or client path in… | |
| Aplazada | Alta (8.2) | 0.55% | — | DeskflowAI | 17/8/2026 | 9/9/2026 | Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after… | |
| Aplazada | Alta (8.2) | 0.45% | — | DeskflowAI | 17/8/2026 | 9/9/2026 | Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the… | |
| Pendiente de análisis | Alta (7.1) | 0.37% | — | Lfprojects MlflowAI | 17/8/2026 | 18/9/2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in mlflow/server/handlers.py verifies only path containment, allowing authenticated… | |
| Pendiente de análisis | Media (6.5) | 0.39% | — | Lfprojects MlflowAI | 17/8/2026 | 18/9/2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any authenticated user to call POST /api/2.0/mlflow/runs/log-inputs for another user's… | |
| Analizada | Crítica (9.3) | 9.8% | ⚠ Explotación activa💥 Exploit | Lfprojects Mlflow | 17/8/2026 | 5/10/2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while… | |
| Aplazada | Alta (7.1) | 0.34% | — | AppflowyAI | 15/8/2026 | 9/9/2026 | AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Roskus Prospero Flow CRMAI | 14/8/2026 | 1/9/2026 | Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password… | |
| Aplazada | Alta (8.6) | 0.39% | — | Roskus Prospero Flow CRMAI | 14/8/2026 | 1/9/2026 | Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to… | |
| Analizada | Crítica (9.1) | 0.61% | — | Langflow | 13/8/2026 | 26/8/2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | |
| Aplazada | Alta (8.6) | 0.59% | — | Roskus Prospero Flow CRMAI | 13/8/2026 | 1/9/2026 | Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that… | |
| Analizada | Alta (7.1) | 0.41% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud… | |
| Analizada | Media (6.3) | 0.33% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID,… | |
| Analizada | Crítica (9) | 0.83% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path traversal checks to load and execute… | |
| Analizada | Crítica (9) | 1.1% | — | Flowiseai Flowise | 13/8/2026 | 4/9/2026 | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing authenticated users to execute arbitrary commands by manipulating environment variables and command arguments. Attackers can abuse PYTHONWARNINGS and BROWSER environment… | |
| Analizada | Media (6) | 0.37% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpoint that allows authenticated attackers to access other customers' payment and profile data by manipulating the customerId parameter. Attackers can enumerate predictable… | |
| Analizada | Crítica (9) | 0.77% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal… | |
| Analizada | Crítica (9) | 0.66% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the… | |
| Analizada | Crítica (9) | 0.60% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to… | |
| Analizada | Alta (8.6) | 0.43% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem. | |
| Analizada | Crítica (9.4) | 0.74% | — | Flowiseai Flowise | 13/8/2026 | 3/9/2026 | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An authenticated user with access to the /api/v1/node-custom-function endpoint can escape the sandbox by supplying attacker-controlled executablePath and args parameters to… | |
| Analizada | Media (6.5) | 0.33% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finished` authorized the target Dag without its team, unlike every other authorization site. A team-aware auth manager distinguishes a team-scoped Dag from a global one by… | |
| Analizada | Media (6.5) | 0.23% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext in task logs and in the Rendered Templates UI. Masking was applied only when the deserialized value was a string or a dict; a list at the top level matched neither and was… | |
| Analizada | Media (6.5) | 0.36% | — | Apache Airflow | 12/8/2026 | 16/9/2026 | Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level request fields, and a bulk request nests its entities two… |