Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.44% | — | AI HUBAI | 13/8/2026 | 14/8/2026 | Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions. | |
| Analizada | Alta (7.5) | 0.52% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the exposure of session tokens in URLs. | |
| Analizada | Media (4.3) | 0.36% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due to improper validation of user-supplied URLs. | |
| Analizada | Crítica (9.3) | 0.57% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to improper neutralization of input during web page generation. | |
| Analizada | Media (5.4) | 0.30% | — | IBM Engineering AI HUB | 17/7/2026 | 24/7/2026 | IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation. | |
| Aplazada | Crítica (10) | 0.46% | — | Liquidthemes AI HUBAI | 15/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to a Web Server.This issue affects AI Hub: from n/a through <= 1.3.7. | |
| Modificada | Crítica (9.8) | 1.1% | — | Aivhub Active Intelligence Visualization | 9/9/2022 | 17/6/2026 | An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanitized. This causes SQL injection. |