Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.47% | — | WindmillAI | 20/8/2026 | 18/9/2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{workspace}/scripts/list_search. The route-level scope middleware validated the token… | |
| Aplazada | Media (5.4) | 0.30% | — | Windmill Labs WindmillAI | 11/8/2026 | 3/9/2026 | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job metrics for any job in the workspace regardless of ownership. The job_metrics handlers accept no authorization extractor, bypassing workspace-level access controls. An… | |
| Aplazada | Media (6.5) | 0.30% | — | Windmill Labs WindmillAI | 11/8/2026 | 3/9/2026 | A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource type schema via the update_resource_type endpoint. The endpoint omits the administrator permission check that the corresponding delete_resource_type endpoint enforces. An… | |
| Aplazada | Media (6.5) | 0.40% | — | Windmill Labs WindmillAI | 11/8/2026 | 3/9/2026 | An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless draft scripts that contain plaintext resource credentials. Drafts with a null owner email bypass ACL enforcement and are returned to any workspace member who queries the… | |
| Aplazada | Alta (8.6) | 0.32% | — | WindmillAI | 19/5/2026 | 14/7/2026 | Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authenticated users to write arbitrary entries to /etc/hosts, /etc/resolv.conf, and /etc/ssl/certs/ca-certificates.crt from within… | |
| Pendiente de análisis | Crítica (9.4) | 14% | — | WindmillAI | 7/4/2026 | 14/7/2026 | Windmill CE and EE versions 1.276.0 through 1.603.2 contain an SQL injection vulnerability in the folder ownership management functionality that allows authenticated attackers to inject SQL through the owner parameter. An attacker can use the injection to read sensitive data such as the JWT signing secret and… | |
| Analizada | Alta (8.7) | 2.6% | — | Nextcloud FlowWindmill | 7/4/2026 | 17/6/2026 | Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability that allows users with the Operator role to perform prohibited entity creation and modification actions via the backend API. Although Operators are documented and priced as unable to create or modify entities, the API does not… | |
| Analizada | Alta (7.3) | 0.57% | — | Windmill | 27/3/2026 | 17/6/2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace environment variable values are interpolated into JavaScript string literals without escaping single quotes in the NativeTS executor. A workspace admin who sets a custom environment variable with a… | |
| Analizada | Media (6.9) | 2.1% | — | Windmill | 6/3/2026 | 17/6/2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename parameter is concatenated… | |
| Analizada | Baja (2.7) | 0.41% | — | Windmill | 20/2/2026 | 17/6/2026 | Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Versions 1.634.6 and below allow non-admin users to obtain Slack OAuth client secrets, which should only be accessible to workspace administrators. The GET /api/w/{workspace}/workspaces/get_settings endpoint… | |
| Aplazada | Media (6.3) | 0.54% | — | WindmillAI | 5/9/2024 | 17/6/2026 | A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the… | |
| Modificada | Crítica (9.3) | 1.3% | — | Windmill Project Windmill | 11/7/2022 | 17/6/2026 | The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |