Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.23% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not have permission to access a target project can reference and invoke a workflow belonging to that project through a sub-workflow task. The system does not properly verify whether the user has… | |
| Aplazada | Media (5.3) | 0.35% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whether authentication is required by matching the incoming request path against protected Actuator paths. By sending a specially crafted request containing a percent-encoded path, a remote unauthenticated… | |
| Aplazada | Media (6.5) | 0.23% | — | Apache DolphinschedulerAI | 29/9/2026 | 1/10/2026 | A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The API does not properly verify whether the authenticated user has permission to access the workflows being queried. An authenticated user who does not have permission to access a specific project can… | |
| Aplazada | Media (4.3) | 0.18% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a project to modify a workflow instance in that project through the PUT /projects/{projectCode}/workflow-instances/{id} endpoint. The endpoint does not enforce the write permission required for this… | |
| Aplazada | Media (4.3) | 0.18% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-move endpoints to operate on workflows in projects for which they lack the required permissions. This may allow the user to copy or move workflows from unauthorized projects. This issue affects… | |
| Aplazada | Alta (8.8) | 0.50% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as… | |
| En análisis | Media (6.5) | 0.23% | — | Apache DolphinschedulerAI | 29/9/2026 | 29/9/2026 | The /datasources/unauth-datasource endpoint does not properly enforce data source authorization. An authenticated user can invoke this endpoint to obtain information about data sources they are not authorized to access. This may expose data source configuration and other sensitive metadata, depending on the fields… | |
| Pendiente de análisis | Alta (8.1) | 0.23% | — | Apache DolphinschedulerAI | 24/9/2026 | 24/9/2026 | A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group. This issue affects Apache DolphinScheduler: before 3.4.3. Users are… | |
| Analizada | Alta (8.8) | 0.58% | — | Apache Dolphinscheduler | 25/8/2026 | 28/9/2026 | General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Aplazada | Media (6.9) | 0.96% | — | Grav Scheduler-webhookAI | 7/8/2026 | 31/8/2026 | Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-circuits and skips token validation, so an unauthenticated remote attacker who can reach POST /scheduler/webhook can… | |
| Aplazada | Media (6.3) | 0.69% | — | Grav Scheduler-webhookAI | 20/7/2026 | 21/7/2026 | Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured scheduled jobs by exploiting a short-circuit logic flaw in the webhook token validation. Attackers can send a single unauthenticated POST request to the scheduler webhook… | |
| Pendiente de análisis | Media (5.1) | 0.17% | — | Microsoft WindowsAIMicrosoft Task SchedulerAIMicrosoft DcomAI | 17/7/2026 | 21/7/2026 | A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3) | |
| Modificada | Media (6.5) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Media (6.5) | 0.49% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access. This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Analizada | Media (4.9) | 0.54% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects This issue affects Apache DolphinScheduler versions prior to 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes this issue. | |
| Modificada | Crítica (9.1) | 0.55% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Modificada | Crítica (9.8) | 0.66% | — | Apache Dolphinscheduler | 17/6/2026 | 17/6/2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue. | |
| Aplazada | Alta (8.6) | 0.16% | — | Splinterware System Scheduler PROAI | 25/5/2026 | 23/7/2026 | Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with… | |
| Aplazada | Crítica (9.8) | 1.0% | — | ApschedulerAI | 19/5/2026 | 24/7/2026 | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object function allows for arbitrary class instantiation and state injection by dynamically importing modules and calling… | |
| Analizada | Alta (8.1) | 0.45% | — | Apache Dolphinscheduler | 24/4/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Apache DolphinScheduler allows authenticated users with system login permissions to use tenants that are not defined on the platform during workflow execution. This issue affects Apache DolphinScheduler versions prior to 3.4.1. Users are recommended to upgrade to version 3.4.1,… | |
| Analizada | Media (6.3) | 0.54% | — | Apache Dolphinscheduler | 24/4/2026 | 5/10/2026 | Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and… | |
| Pendiente de análisis | Alta (7.7) | 0.24% | — | Nvidia KAI SchedulerAI | 21/4/2026 | 17/6/2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could access API endpoints without authorization. A successful exploit of this vulnerability might lead to information disclosure. | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Nvidia KAI SchedulerAI | 21/4/2026 | 17/6/2026 | NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/user/manage_user.php. | |
| Aplazada | Baja (2.7) | 0.31% | — | Sourcecodester Patient Appointment Scheduler SystemAI | 14/4/2026 | 17/6/2026 | SourceCodester Patient Appointment Scheduler System v1.0 is vulnerable to SQL Injection in the file /scheduler/admin/appointments/manage_appointment.php. |