Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
3557 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.23% | — | Interprobe Information Technologies Qorela DCAI | 29/9/2026 | 29/9/2026 | Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2. | |
| Aplazada | Media (6.1) | 0.15% | — | Rolantis Information Technologies AgentisAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Automation WEB PlatformAI | 25/9/2026 | 25/9/2026 | The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/<op>` and… | |
| Pendiente de análisis | Media (6.8) | 0.45% | — | Redhat Ansible Automation PlatformAI | 24/9/2026 | 24/9/2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an… | |
| Pendiente de análisis | Alta (7.2) | 0.43% | — | Ansible Automation PlatformAIRsyslogAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and LOG_AGGREGATOR_RSYSLOGD_ERROR_LOG_FILE — into an rsyslog RainerScript config file… | |
| Pendiente de análisis | Media (6.6) | 0.29% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 26/9/2026 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command… | |
| Pendiente de análisis | Media (6.4) | 0.17% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 24/9/2026 | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback,… | |
| Pendiente de análisis | Media (6.5) | 0.27% | — | Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore accepted for arbitrary field lookups by the REST… | |
| Pendiente de análisis | Crítica (9.9) | 0.43% | — | Ansible Automation PlatformAIAnsible Automation-controllerAI | 23/9/2026 | 25/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that… | |
| Pendiente de análisis | Media (4.3) | 0.14% | — | Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacker-controlled)… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a… | |
| Pendiente de análisis | Media (6.6) | 0.18% | — | Redhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Redhat Automation-controllerAIAnsible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | Ansible Automation ControllerAI | 23/9/2026 | 25/9/2026 | — | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Redhat Ansible Automation ControllerAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.6) | 0.31% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD,… | |
| Pendiente de análisis | Alta (8.7) | 0.20% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute… | |
| Pendiente de análisis | Alta (8.7) | 0.26% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 25/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the… | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | — | Redhat Ansible Automation PlatformAIRedhat AWXAI | 23/9/2026 | 24/9/2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate… | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"… | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller… | |
| Pendiente de análisis | Alta (8.2) | 0.52% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | Redhat Ansible Automation PlatformAI | 23/9/2026 | 24/9/2026 | — | |
| Aplazada | Alta (8.1) | 0.49% | — | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting… |