Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.41% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note:… | |
| Analizada | Alta (8.5) | 0.26% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+18 | 13/5/2026 | 29/6/2026 | A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.9) | 0.89% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/5/2026 | 29/6/2026 | When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Aplazada | Alta (7.5) | 0.69% | — | Aiwu AI Chatbot Workflow AutomationAI | 12/5/2026 | 17/6/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This makes it possible for… | |
| Analizada | Alta (8.8) | 0.34% | — | Dell Automation Platform | 11/5/2026 | 17/6/2026 | Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Crítica (9.6) | 0.40% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS). This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Media (6.5) | 0.17% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.8) | 0.45% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 17/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2. | |
| Aplazada | Alta (8.3) | 0.22% | — | Divvydrive Information Technologies INC DivvydriveAI | 7/5/2026 | 5/10/2026 | Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Excessive Allocation, Flooding. This issue affects DivvyDrive: from 4.8.2.19 before 4.8.3.2. | |
| Pendiente de análisis | Alta (8.3) | 0.57% | — | Redhat Ansible Automation PlatformAI | 4/5/2026 | 26/8/2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or… | |
| Aplazada | Alta (7.2) | 1.7% | — | Profelis Information AND Consulting Trade AND Industry Limited Company SambaboxAI | 4/5/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3. | |
| Analizada | Alta (8.8) | 0.50% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Analizada | Crítica (9.8) | 0.61% | — | Progress Moveit Automation | 30/4/2026 | 17/6/2026 | Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Bypass. This issue affects MOVEit Automation: from 2025.0.0 before 2025.0.9, from 2024.0.0 before 2024.1.8, versions prior to 2024.0.0. | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Redhat Ansible Automation PlatformAI | 17/4/2026 | 17/6/2026 | A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as… | |
| Aplazada | Crítica (9.1) | 0.42% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php. | |
| Aplazada | Media (4.7) | 0.27% | — | Sourcecodester Payroll Management AND Information SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_account.php?emp_id=. | |
| Pendiente de análisis | Baja (2) | 0.24% | — | SAP Landscape TransformationAI | 14/4/2026 | 17/6/2026 | SAP Landscape Transformation contains a vulnerability in an RFC-exposed function module that could allow a high privileged adversary to inject arbitrary ABAP code and operating system commands. Due to this, some information could be modified, but the attacker does not have control over kind or degree. This leads to a… | |
| Analizada | Media (6.4) | 0.14% | — | Redhat Process Automation Manager | 8/4/2026 | 24/7/2026 | A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Modificada | Media (6.4) | 0.18% | — | Redhat Ansible Automation Platform | 8/4/2026 | 24/9/2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Aplazada | Media (6.5) | 0.22% | — | Wealcoder Animation Addons FOR ElementorAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wealcoder Animation Addons for Elementor animation-addons-for-elementor allows DOM-Based XSS.This issue affects Animation Addons for Elementor: from n/a through <= 2.6.1. | |
| Aplazada | Media (5.3) | 0.29% | — | Massiveshift AI Workflow Automation LiteAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in massiveshift AI Workflow Automation ai-workflow-automation-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Workflow Automation: from n/a through <= 1.4.2. | |
| Pendiente de análisis | Media (6) | 0.26% | — | Pega Browser ExtensionAIPega Robotic AutomationAI | 7/4/2026 | 17/6/2026 | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a website that contains malicious code that targets PBE. The vulnerability could occur if a user navigates to this website.… | |
| Pendiente de análisis | Alta (7.2) | 0.32% | — | Pega Browser ExtensionAIPega Robotic AutomationAI | 7/4/2026 | 17/6/2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime… | |
| Analizada | Alta (8.8) | 0.27% | — | Gatech Computing FOR Good's Basic Laboratory Information System | 5/4/2026 | 24/7/2026 | C4G Basic Laboratory Information System 3.4 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the site parameter. Attackers can send GET requests to the users_select.php endpoint with crafted SQL payloads to… |