Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.25%—Omnisend Newsletters Email Marketing SMS AND PopupsAI30/9/202630/9/2026
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
AplazadaCrítica (9.3)0.24%—Omni C20AI24/9/202624/9/2026
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
AplazadaMedia (6.8)0.11%—Omni C20AI24/9/202624/9/2026
Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.
Pendiente de análisisMedia (5.3)0.45%—OmniblocksAI17/9/202623/9/2026
OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenever an issue is classified as off-topic, without recording that the issue was…
AplazadaAlta (7.6)0.14%—KubernetesAITalosAIEtcdAISiderolabs OmniAI17/9/202624/9/2026
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access rules in internal/backend/runtime/omni/state_access.go allow an…
Pendiente de análisisBaja (2.7)0.49%—TalosAISiderolabs OmniAI17/9/202623/9/2026
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVersions without validating it as a version. An authenticated Operator…
AplazadaAlta (7)0.14%—Siderolabs OmniAI17/9/202624/9/2026
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Concurrent requests carrying the same captured saml-session token can…
AplazadaCrítica (9.5)1.4%—OmnirouteAI10/9/202630/9/2026
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency check before execFileSync executed the…
AplazadaCrítica (9.3)0.39%—Auth0 JsonwebtokenAIOmnivoreAI29/8/202624/9/2026
The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which…
AplazadaAlta (8.8)0.61%—OmnigentAI21/8/202618/9/2026
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent bundle with an absolute or traversal-containing os_env.cwd value because omnigent/spec/parser.py stores the value verbatim and…
AplazadaAlta (7.1)0.40%—OmnigentAI21/8/202618/9/2026
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in omnigent/policies/builtins/_shell.py fails to recognize combined interpreter flags, the timeout, nice, setsid, and stdbuf wrappers, command substitutions, and a single…
AplazadaAlta (8.8)0.65%—OmnigentAI21/8/202618/9/2026
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle does not reject a tools..callable dotted Python path.…
AplazadaCrítica (9)0.51%—OmnigentAI21/8/202618/9/2026
Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An authenticated user with edit access to a…
AnalizadaAlta (7.8)0.18%—Omnissa Workspace ONE Tunnel8/7/202610/7/2026
Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
AplazadaMedia (5.4)0.29%—Omnisend Email Marketing FOR WoocommerceAI26/6/202626/6/2026
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
AplazadaAlta (7.5)0.48%—Omnisend Email Marketing FOR WoocommerceAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
Pendiente de análisisAlta (7.8)0.13%—Omnissa Workspace ONE AssistAI9/6/202623/7/2026
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
AplazadaAlta (8.1)0.63%—OmnifacesAI8/5/202617/6/2026
OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server-side EL injection leading to Remote Code Execution (RCE). This affects applications that use CDNResourceHandler with a wildcard CDN mapping (e.g. libraryName:*=https://cdn.example.com/*). An…
AplazadaMedia (5.5)0.51%—Newgensoft OmnidocsAI2/4/202624/7/2026
A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack may be performed from remote. The…
AplazadaBaja (2.9)0.46%—Newgensoft OmnidocsAI2/4/202624/7/2026
A vulnerability was identified in Newgen OmniDocs up to 12.0.00. Affected by this vulnerability is an unknown functionality of the file /omnidocs/GetWebApiConfiguration. The manipulation of the argument connectionDetails leads to information disclosure. The attack is possible to be carried out remotely. The attack is…
AplazadaBaja (2.3)0.41%—Omnipemf NeorhythmAI21/3/202616/9/2026
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. The attack can only be initiated within the local network. This attack is characterized by high complexity. The…
Pendiente de análisisCrítica (9.3)1.5%—Omnigen2-rlAI18/3/202614/7/2026
OmniGen2-RL contains an unauthenticated remote code execution vulnerability in the reward server component that allows remote attackers to execute arbitrary commands by sending malicious HTTP POST requests. Attackers can exploit insecure pickle deserialization of request bodies to achieve code execution on the host…
AplazadaMedia (6.5)0.23%—Omnipressteam OmnipressAI19/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress omnipress allows Stored XSS.This issue affects Omnipress: from n/a through <= 1.6.7.
AnalizadaAlta (7.5)0.42%—Newgensoft Omniapp23/1/202617/6/2026
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource.
AplazadaAlta (7.5)0.45%—Omnipressteam OmnipressAIPHPAI23/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in omnipressteam Omnipress omnipress allows PHP Local File Inclusion.This issue affects Omnipress: from n/a through <= 1.6.7.