Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2806▲ 5 respecto a la semana anterior
Críticas / altas1465▲ 246 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)77▼ 441 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.3) | 0.30% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a security… | |
| Pendiente de análisis | Alta (8.7) | 0.29% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete instance data beyond what was intended. In August 2026, ServiceNow deployed a security… | |
| Pendiente de análisis | Alta (8.4) | 0.24% | — | Servicenow AI PlatformAI | 24/9/2026 | 25/9/2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling… | |
| Pendiente de análisis | Crítica (9.3) | 0.27% | — | Servicenow AI PlatformAI | 24/9/2026 | 24/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Praisonai PlatformAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated… | |
| Aplazada | Crítica (9.8) | 0.77% | — | Praisonai PlatformAI | 15/9/2026 | 17/9/2026 | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote… | |
| Pendiente de análisis | Crítica (10) | 0.42% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data… | |
| Pendiente de análisis | Crítica (10) | 0.62% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow AI Platform than intended. ServiceNow… | |
| Pendiente de análisis | Crítica (10) | 5.0% | — | Servicenow AI PlatformAI | 27/8/2026 | 3/9/2026 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. ServiceNow deployed a… | |
| Pendiente de análisis | Crítica (10) | 7.2% | — | Servicenow AI PlatformAI | 27/8/2026 | 1/9/2026 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended.… | |
| Aplazada | Alta (8.8) | 0.44% | — | Praisonai Platform APIAI | 7/8/2026 | 18/9/2026 | PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read,… | |
| Aplazada | Crítica (9.6) | 0.36% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and… | |
| Aplazada | Alta (8.3) | 0.39% | — | Praisonai PlatformAI | 21/7/2026 | 21/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue_id}`) gate access on `require_workspace_member(workspace_id)` only, then… | |
| Aplazada | Alta (7.6) | 0.38% | — | Praisonai PlatformAI | 21/7/2026 | 23/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .../labels/{label_id}`, `POST .../issues/{issue_id}/labels/{label_id}`, `DELETE… | |
| Aplazada | Crítica (9.6) | 0.36% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`) and… | |
| Aplazada | Alta (8.1) | 0.53% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of… | |
| Aplazada | Media (6.5) | 0.34% | — | Praisonai PlatformAI | 21/7/2026 | 21/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default… | |
| Aplazada | Crítica (9.8) | 0.64% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when… | |
| Aplazada | Media (6.5) | 0.40% | — | Praisonai PlatformAI | 21/7/2026 | 23/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_workspace_member(workspace_id)` and dispatches to… | |
| Aplazada | Alta (8.1) | 0.41% | — | Praisonai PlatformAI | 21/7/2026 | 21/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE .../dependencies/{dep_id}`) gate access on… | |
| Aplazada | Alta (8.8) | 0.51% | — | Praisonai PlatformAI | 21/7/2026 | 21/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to `owner`. The issue is caused by privileged workspace-management routes… | |
| Aplazada | Alta (8.8) | 0.51% | — | Praisonai PlatformAI | 21/7/2026 | 22/7/2026 | PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by… | |
| Aplazada | Alta (7.1) | 0.38% | — | Praisonai PlatformAI | 15/7/2026 | 18/7/2026 | PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label… | |
| Pendiente de análisis | Crítica (9.5) | 1.4% | — | Servicenow AI PlatformAI | 13/7/2026 | 14/7/2026 | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to… |