Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.32% | — | Trigger.devAI | 16/9/2026 | 23/9/2026 | Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and supplying sequential installation identifiers, gaining unauthorized access to the… | |
| Aplazada | Alta (8.4) | 0.49% | — | Trigger DEVAI | 4/9/2026 | 23/9/2026 | Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to consume victim resources and pollute run… | |
| Aplazada | Media (5.3) | 0.35% | — | Trigger.devAI | 4/9/2026 | 23/9/2026 | Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal services and metadata endpoints, allowing… | |
| Pendiente de análisis | Media (4.3) | 0.19% | — | Jenkins Parameterized Remote Trigger PluginAI | 2/9/2026 | 3/9/2026 | Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Alta (8.1) | 0.51% | — | Trigger.devAI | 13/8/2026 | 8/9/2026 | Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app/routes/api.v1.packets.$.ts pass a caller-controlled filename through resolveStoreProtocolForPacketPresign to generatePresignedUrl and generatePresignedRequest in… | |
| Aplazada | Alta (8.2) | 0.41% | — | Trigger DEVAI | 13/8/2026 | 8/9/2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and Aws4FetchClient.presign() in apps/webapp/app/v3/objectStoreClient.server.ts assign user-controlled packet keys to URL.pathname, while… | |
| Aplazada | Media (4.2) | 0.18% | — | Trigger.devAI | 13/8/2026 | 8/9/2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in apps/webapp/app/routes/api.v1.runs.$runParam.replay.ts uses `prisma.taskRun.findUnique({ where: { friendlyId: runParam } })` without a runtimeEnvironmentId… | |
| Aplazada | Crítica (9.9) | 0.50% | — | Trigger.devAI | 13/8/2026 | 18/9/2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWorkerV4.server.ts, where… | |
| Aplazada | Alta (7.4) | 0.47% | — | Trigger.devAI | 13/8/2026 | 18/9/2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified… | |
| Aplazada | Alta (8.5) | 0.62% | — | Trigger DEVAI | 13/8/2026 | 18/9/2026 | Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes attacker-controlled operation.key values to new JSONHeroPath(operation.key).set(newMetadata, value) in packages/core/src/v3/runMetadata/operations.ts… | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Parameterized Remote TriggerAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Analizada | Media (6.1) | 0.17% | — | Jontasc Sailthru Triggermail | 15/5/2025 | 17/6/2026 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings and is missing CSRF protection which could allow subscribers to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Crítica (9.8) | 54% | — | Brainstormforce OttokitAIBrainstormforce SuretriggersAI | 1/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Brainstorm Force OttoKit suretriggers allows Privilege Escalation.This issue affects OttoKit: from n/a through <= 1.0.82. | |
| Aplazada | Alta (8.1) | 76% | — | SuretriggersAI | 10/4/2025 | 17/6/2026 | The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible… | |
| Analizada | Media (4.8) | 0.30% | — | Wptriggers WP Triggers Lite | 27/1/2025 | 17/6/2026 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | |
| Analizada | Alta (7.1) | 0.57% | — | Wptriggers WP Triggers Lite | 27/1/2025 | 17/6/2026 | The WP Triggers Lite WordPress plugin through 2.5.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.4) | 0.36% | — | SuretriggersAI | 4/6/2024 | 17/6/2026 | The SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Trigger Link shortcode in all versions up to, and including, 1.0.47 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Analizada | Alta (7.1) | 0.39% | — | Jontasc Sailthru Triggermail | 21/5/2024 | 17/6/2026 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.1) | 0.37% | — | Jontasc Sailthru Triggermail | 21/5/2024 | 17/6/2026 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (5.4) | 0.33% | — | Noahkagan Scroll Triggered BOX | 5/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: from n/a through 2.3. | |
| Modificada | Alta (8.8) | 0.26% | — | Suretriggers | 15/12/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SureTriggers SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!.This issue affects SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything!: from n/a through 1.0.23. | |
| Modificada | Media (5.3) | 0.57% | — | Jenkins Msteams Webhook Trigger | 25/10/2023 | 17/6/2026 | Jenkins MSTeams Webhook Trigger Plugin 0.1.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (5.3) | 0.56% | — | Jenkins Multibranch Scan Webhook Trigger | 25/10/2023 | 17/6/2026 | Jenkins Multibranch Scan Webhook Trigger Plugin 1.0.9 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token. | |
| Modificada | Media (6.1) | 0.50% | — | Jenkins AWS Codecommit Trigger | 6/9/2023 | 17/6/2026 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability. | |
| Modificada | Media (6.5) | 0.64% | — | Jenkins AWS Codecommit Trigger | 6/9/2023 | 17/6/2026 | Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to clear the SQS queue. |