Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Crítica (9.3) | 0.24% | — | Omni C20AI | 24/9/2026 | 24/9/2026 | Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code. | |
| Aplazada | Media (6.8) | 0.11% | — | Omni C20AI | 24/9/2026 | 24/9/2026 | Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data. | |
| Pendiente de análisis | Media (5.3) | 0.45% | — | OmniblocksAI | 17/9/2026 | 23/9/2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was… | |
| Aplazada | Alta (7.6) | 0.14% | — | KubernetesAITalosAIEtcdAISiderolabs OmniAI | 17/9/2026 | 24/9/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an… | |
| Pendiente de análisis | Baja (2.7) | 0.49% | — | TalosAISiderolabs OmniAI | 17/9/2026 | 23/9/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions without validating it as a version. An authenticated Operator… | |
| Aplazada | Alta (7) | 0.14% | — | Siderolabs OmniAI | 17/9/2026 | 24/9/2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can… | |
| Aplazada | Crítica (9.5) | 1.4% | — | OmnirouteAI | 10/9/2026 | 30/9/2026 | OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the… | |
| Aplazada | Crítica (9.3) | 0.39% | — | Auth0 JsonwebtokenAIOmnivoreAI | 29/8/2026 | 24/9/2026 | The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which… | |
| Aplazada | Alta (8.8) | 0.61% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnigent/spec/parser.py stores the value verbatim and… | |
| Aplazada | Alta (7.1) | 0.40% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single… | |
| Aplazada | Alta (8.8) | 0.65% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path.… | |
| Aplazada | Crítica (9) | 0.51% | — | OmnigentAI | 21/8/2026 | 18/9/2026 | Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a… | |
| Analizada | Alta (7.8) | 0.18% | — | Omnissa Workspace ONE Tunnel | 8/7/2026 | 10/7/2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. | |
| Aplazada | Media (5.4) | 0.29% | — | Omnisend Email Marketing FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | |
| Aplazada | Alta (7.5) | 0.48% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Omnissa Workspace ONE AssistAI | 9/6/2026 | 23/7/2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. | |
| Aplazada | Alta (8.1) | 0.63% | — | OmnifacesAI | 8/5/2026 | 17/6/2026 | OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example.com/*). An… | |
| Aplazada | Media (5.5) | 0.51% | — | Newgensoft OmnidocsAI | 2/4/2026 | 24/7/2026 | A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack may be performed from remote. The… | |
| Aplazada | Baja (2.9) | 0.46% | — | Newgensoft OmnidocsAI | 2/4/2026 | 24/7/2026 | A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails leads to information disclosure. The attack is possible to be carried out remotely. The attack is… | |
| Aplazada | Baja (2.3) | 0.41% | — | Omnipemf NeorhythmAI | 21/3/2026 | 16/9/2026 | A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The… | |
| Pendiente de análisis | Crítica (9.3) | 1.5% | — | Omnigen2-rlAI | 18/3/2026 | 14/7/2026 | OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execution on the host… | |
| Aplazada | Media (6.5) | 0.23% | — | Omnipressteam OmnipressAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.6.7. | |
| Analizada | Alta (7.5) | 0.42% | — | Newgensoft Omniapp | 23/1/2026 | 17/6/2026 | An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource. | |
| Aplazada | Alta (7.5) | 0.45% | — | Omnipressteam OmnipressAIPHPAI | 23/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File Inclusion.This issue affects Omnipress: from n/a through <= 1.6.7. |