Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2509▼ 448 respecto a la semana anterior
Críticas / altas1286▼ 7 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 464 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.83%—Jenkins Robot Framework PluginAI16/9/202618/9/2026
Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framework report files is contained within the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file…
AplazadaAlta (7)0.66%—NanobotAIMicrosoft TeamsAIMicrosoft BOT FrameworkAI1/6/202622/7/2026
Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework bearer tokens by supplying a forged activity with an attacker-controlled serviceUrl value. Attackers can poison the stored conversation…
AplazadaAlta (8.3)0.36%—Discord BOT Framework KernelAI18/2/202517/6/2026
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By…
ModificadaCrítica (9.8)2.8%—Microsoft BOT Framework Software Development KIT15/12/202117/6/2026
Bot Framework SDK Remote Code Execution Vulnerability
ModificadaMedia (5.5)1.1%—Microsoft BOT Framework Software Development KIT12/1/202117/6/2026
Bot Framework SDK Information Disclosure Vulnerability
ModificadaAlta (8.8)1.4%—Jenkins Robot Framework15/1/202017/6/2026
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with Job/Configure to have Jenkins parse crafted XML documents.