Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
8596 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.64% | — | Praisonai PlatformAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.77% | — | Praisonai PlatformAI | 15/9/2026 | 17/9/2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote… | |
| Aplazada | Media (5.3) | 0.34% | — | Steedos PlatformAI | 15/9/2026 | 24/9/2026 | Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft malicious links with script-terminating sequences in the schemaApi or data parameters… | |
| Aplazada | Media (6.3) | 0.37% | — | Huly PlatformAIPuppeteerAI | 14/9/2026 | 24/9/2026 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as downloadable PDFs or images, enabling access to… | |
| Aplazada | Alta (8.7) | 0.51% | — | ConformAI | 14/9/2026 | 30/9/2026 | Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or URLSearchParams entries by each unique field name. An unauthenticated attacker can… | |
| Aplazada | Alta (8.2) | 1.1% | — | Xwiki PlatformAIEclipse JettyAIApache TomcatAI | 14/9/2026 | 30/9/2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced… | |
| Analizada | Media (5.5) | 0.16% | — | Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux | 14/9/2026 | 7/10/2026 | A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability… | |
| Aplazada | Baja (2.1) | 0.37% | — | Wxiaoqi Spring Cloud PlatformAI | 13/9/2026 | 15/9/2026 | A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation results in missing authorization. The attack can be executed remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.37% | — | Wxiaoqi Spring Cloud PlatformAI | 13/9/2026 | 14/9/2026 | A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Service. The manipulation leads to missing authorization. Remote exploitation of the… | |
| Aplazada | Media (5.1) | 0.35% | — | Tduckcloud Tduck-platformAI | 13/9/2026 | 14/9/2026 | A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes cross site scripting. The attack is… | |
| Aplazada | Media (5.3) | 0.34% | — | Contact Form TO Chat AppsAI | 13/9/2026 | 14/9/2026 | The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entries of any form created with a supported third-party form Contact Form to Chat Apps |… | |
| Aplazada | Media (6.5) | 0.45% | — | E-goi Smart Marketing SMS AND Newsletters FormsAI | 12/9/2026 | 14/9/2026 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via Parameter Name in all versions up to, and including, 5.1.24 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Alta (8.6) | 0.45% | — | Samo FormsAI | 12/9/2026 | 14/9/2026 | The SAMO Forms WordPress plugin through 1.0.0 does not properly sanitise and escape user input before using it in SQL queries in several unauthenticated actions, allowing unauthenticated attackers to perform SQL injection attacks. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wpeverest Everest FormsAI | 11/9/2026 | 11/9/2026 | Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. | |
| Aplazada | Media (6.1) | 0.26% | — | IBM Marketing PlatformAI | 11/9/2026 | 22/9/2026 | A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL into the ca parameter. | |
| Pendiente de análisis | Crítica (9.2) | 0.44% | — | Akana API PlatformAI | 11/9/2026 | 18/9/2026 | A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a… | |
| Aplazada | Media (4.8) | 0.24% | — | MetformAI | 11/9/2026 | 11/9/2026 | The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends when a submitted field value is… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Aplazada | Media (6.5) | 0.33% | — | Themekraft BuddyformsAI | 10/9/2026 | 10/9/2026 | Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. | |
| Aplazada | Alta (7.5) | 0.50% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.3) | 0.36% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Armiya Information Technologies LTD Access Control SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2. | |
| Aplazada | Alta (7.2) | 0.46% | — | Registration Form FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can… | |
| Aplazada | Media (6.1) | 0.38% | — | 10web Form MakerAI | 10/9/2026 | 11/9/2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficient input sanitization and output escaping. This makes it possible for… |