Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 299 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
14.200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | — | — | Nasa-ammos Ait-coreAI | 3/10/2026 | 3/10/2026 | CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry… | |
| Recibida | Alta (7.2) | 0.24% | — | Jamesward WP Mail CatcherAI | 3/10/2026 | 3/10/2026 | The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Recibida | Media (5.3) | 0.18% | — | Mailchimp FOR WoocommerceAI | 3/10/2026 | 3/10/2026 | The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart. | |
| Recibida | Media (4.3) | 0.21% | — | Alttext ALT Text AIAI | 3/10/2026 | 3/10/2026 | The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.10.41. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for… | |
| Recibida | Alta (8.8) | 0.17% | — | Kubio AI Page BuilderAI | 3/10/2026 | 3/10/2026 | The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before… | |
| Recibida | Media (6.8) | 0.15% | — | Kubio AI Page BuilderAI | 3/10/2026 | 3/10/2026 | The Kubio AI Page Builder WordPress plugin before 2.9.3 does not validate the URI scheme of a user-supplied value before outputting it as a link target, allowing users with the contributor role and above to store a payload which executes in the browser of anyone who follows the link, including an administrator… | |
| Recibida | Alta (7.6) | 0.25% | — | Langchain Langgraph SDKAI | 2/10/2026 | 2/10/2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. From 0.1.45 until 0.4.4, the langgraph-sdk resource-scoped authorization decorators @auth.on.threads, @auth.on.assistants, and @auth.on.crons ignore the actions argument and… | |
| Recibida | Media (6.5) | 0.18% | — | Aioseo ALL IN ONE SEOAI | 2/10/2026 | 2/10/2026 | The All in One SEO WordPress plugin before 5.0.2.1 does not correctly determine which shortcodes are present in content derived from user input before deciding which ones to strip, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. On sites upgraded from older versions the… | |
| Aplazada | Alta (8.1) | 0.39% | — | Taskingai QR Code GeneratorAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Aplazada | Sin puntuar | 0.14% | — | TaskingaiAI | 2/10/2026 | 2/10/2026 | In TaskingAI v0.3.0 in the DALL-E 3 image generation tool save_url_image function, a path traversal vulnerability allows attackers to write downloaded images to arbitrary locations on the server filesystem by manipulating the project_id parameter. | |
| Pendiente de análisis | Sin puntuar | 0.16% | — | Sinaptik AI Pandas-aiAI | 2/10/2026 | 2/10/2026 | sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | |
| Pendiente de análisis | Crítica (9.9) | 0.94% | — | Gitlab AI GatewayAI | 2/10/2026 | 2/10/2026 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template… | |
| Aplazada | Media (4.7) | 0.17% | — | Mehul Gohil Aculect AI CompanionAI | 2/10/2026 | 2/10/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1. | |
| Aplazada | Media (6.5) | 0.19% | — | Kiera Howe WebsamuraiAI | 2/10/2026 | 2/10/2026 | Missing Authorization vulnerability in Kiera Howe WebSamurai websamurai allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebSamurai: from n/a through 1.0.7. | |
| Aplazada | Media (6.5) | 0.17% | — | Airano MCP BridgeAI | 2/10/2026 | 3/10/2026 | Missing Authorization vulnerability in airano Airano MCP Bridge airano-mcp-bridge allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Airano MCP Bridge: from n/a through 2.11.0. | |
| Aplazada | Media (6.1) | 0.21% | — | Aioseo ALL IN ONE SEOAI | 2/10/2026 | 3/10/2026 | The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (7.4) | 0.16% | — | Havelsan SEF AI Chatbot PlatformAI | 2/10/2026 | 2/10/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Alta (7.2) | 0.31% | — | Kubio AI Page BuilderAI | 2/10/2026 | 3/10/2026 | The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'comment' parameter in all versions up to, and including, 2.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.22% | — | Awesomemotive WP Mail LoggingAI | 2/10/2026 | 2/10/2026 | The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log… | |
| Aplazada | Media (5.3) | 0.25% | — | CMP Coming Soon MaintenanceAI | 2/10/2026 | 2/10/2026 | The CMP – Coming Soon & Maintenance WordPress plugin before 4.1.20 does not correctly restrict access to the site while maintenance/coming-soon mode is enabled, allowing unauthenticated visitors to bypass the coming-soon page and reach the otherwise hidden site, including hidden published pages, by shaping the request… | |
| Aplazada | Sin puntuar | 0.15% | — | Langchain ChatchatAI | 1/10/2026 | 2/10/2026 | The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory. | |
| Aplazada | Sin puntuar | 0.14% | — | Chatchat-space Langchain-chatchatAI | 1/10/2026 | 2/10/2026 | The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge… | |
| Aplazada | Sin puntuar | 0.14% | — | Chatchat-space Langchain-chatchatAI | 1/10/2026 | 2/10/2026 | The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames. | |
| Aplazada | Sin puntuar | 0.14% | — | Stitionai DevikaAI | 1/10/2026 | 2/10/2026 | In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially compromising the entire server. | |
| Aplazada | Sin puntuar | 0.15% | — | Stitionai DevikaAI | 1/10/2026 | 2/10/2026 | In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace. |