Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
4530 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.6) | — | — | Progress Software Autonomous Rest Connector Genai AgentsAI | 6/10/2026 | 6/10/2026 | An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user… | |
| Aplazada | Media (6.5) | 0.33% | — | Autoship CloudAI | 6/10/2026 | 6/10/2026 | Missing Authorization vulnerability in Patterns In The Cloud Autoship Cloud for WooCommerce Subscription Products autoship-cloud allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Autoship Cloud for WooCommerce Subscription Products: from n/a through 2.17.1. | |
| Aplazada | Alta (8.4) | 0.22% | — | Auto-changelogAI | 5/10/2026 | 6/10/2026 | auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over… | |
| Aplazada | Media (5.4) | 0.22% | — | AutoptimizeAI | 2/10/2026 | 3/10/2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Aplazada | Alta (7.2) | 0.28% | — | AutoptimizeAI | 1/10/2026 | 1/10/2026 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Pendiente de análisis | Alta (7.1) | 0.48% | — | PX4 AutopilotAI | 29/9/2026 | 30/9/2026 | PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller. | |
| Pendiente de análisis | Alta (7.1) | 0.24% | — | PX4 AutopilotAI | 29/9/2026 | 2/10/2026 | PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the… | |
| Aplazada | Alta (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 29/9/2026 | 30/9/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Aplazada | Media (5.9) | 0.19% | — | Nextscripts Social Networks Auto PosterAI | 27/9/2026 | 28/9/2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership checks on several of its AJAX actions, relying on a nonce alone, allowing users an administrator has granted access to its posting features to export the site's configured social account credentials,… | |
| Aplazada | Media (6.4) | 0.21% | — | Automatic.cssAI | 26/9/2026 | 28/9/2026 | The Automatic.css plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI in all version 4.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that will execute whenever an administrator accesses… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Automation WEB PlatformAI | 25/9/2026 | 25/9/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and… | |
| Pendiente de análisis | Media (6.8) | 0.45% | — | Redhat Ansible Automation PlatformAI | 24/9/2026 | 24/9/2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an… | |
| Pendiente de análisis | Alta (7.2) | 0.43% | — | Ansible Automation PlatformAIRsyslogAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config file… | |
| Pendiente de análisis | Media (6.6) | 0.29% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 26/9/2026 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command… | |
| Pendiente de análisis | Media (6.4) | 0.17% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 24/9/2026 | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback,… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST… | |
| Pendiente de análisis | Crítica (9.9) | 0.43% | — | Ansible Automation PlatformAIAnsible Automation-controllerAI | 23/9/2026 | 25/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that… | |
| Pendiente de análisis | Media (4.3) | 0.14% | — | Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled)… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a… | |
| Pendiente de análisis | Media (6.6) | 0.18% | — | Redhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Redhat Automation-controllerAIAnsible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | Ansible Automation ControllerAI | 23/9/2026 | 25/9/2026 | — | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Redhat Ansible Automation ControllerAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.6) | 0.31% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD,… | |
| Pendiente de análisis | Alta (8.7) | 0.20% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute… |