Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.51% | — | Stability AI Stable Diffusion WebuiAI | 21/8/2026 | 24/9/2026 | to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic links. A symlink placed inside a scanned directory therefore satisfies the containment comparison performed by is_path_trusted in scripts/iib/api.py while pointing outside… | |
| Analizada | Media (6.5) | 0.84% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application. | |
| Analizada | Media (6.1) | 0.42% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's… | |
| Analizada | Media (6.5) | 0.82% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server… | |
| Analizada | Crítica (9.6) | 0.41% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join,… | |
| Analizada | Media (6.1) | 0.83% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials. | |
| Modificada | Alta (7.5) | 0.82% | — | Automatic1111 Stable-diffusion-webui | 20/3/2025 | 17/6/2026 | automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive… | |
| Aplazada | Media (6.3) | 0.68% | — | GradioAIAutomatic1111 Stable-diffusion-webuiAI | 12/4/2024 | 17/6/2026 | stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on… | |
| Modificada | Alta (7.5) | 0.57% | — | Zanllp Stable Diffusion Webui Infinite Image Browsing | 22/10/2023 | 17/6/2026 | The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated… |