Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
310 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.7) | 0.23% | — | Brainstormforce AstraAI | 30/9/2026 | 30/9/2026 | Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. | |
| Aplazada | Alta (8.1) | 0.21% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Control-Allow-Origin` while also sending `Access-Control-Allow-Credentials: true`. The… | |
| Aplazada | Media (4.3) | 0.28% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag with the authorizer result in a way that discarded the authorizer's answer whenever the flag… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried in the frame, so a single frame from an unauthenticated peer able to reach a worker… | |
| Aplazada | Crítica (10) | 0.50% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only topology permissions, so a user whose only grant was the… | |
| Aplazada | Media (6.5) | 0.34% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and the keystore and truststore passwords for the Thrift, Netty and ZooKeeper TLS… | |
| Aplazada | Alta (8.1) | 0.37% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validation, so a caller authorised to rebalance a topology could introduce a blobstore map… | |
| Aplazada | Crítica (9.8) | 0.39% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.users` unset, therefore received no restriction at all: every authenticated principal… | |
| Aplazada | Alta (7.8) | 0.14% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW`… | |
| Aplazada | Alta (7.8) | 0.13% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has… | |
| Aplazada | Alta (8.8) | 0.69% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and predictable in advance. When the blob already existed, the uploader caught… | |
| Aplazada | Alta (7.8) | 0.15% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper… | |
| Aplazada | Media (6.5) | 0.42% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. The intended flow is that a client first calls `beginFileUpload`, which returns a… | |
| Aplazada | Media (6.5) | 0.43% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description | |
| Aplazada | Crítica (9.1) | 0.27% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on the submission path, yet acts on them in two places. During cleanup of a finished… | |
| Aplazada | Crítica (9.8) | 0.34% | — | Apache StormAI | 14/9/2026 | 14/9/2026 | Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shutdown path drained queues, but the queue object and its map entry remained for the… | |
| Aplazada | Alta (7.2) | 0.29% | — | Brainstormforce SureformsAI | 5/9/2026 | 8/9/2026 | The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.16% | — | Stormshield SNSAI | 4/9/2026 | 8/9/2026 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface. | |
| Aplazada | Baja (2.1) | 0.37% | — | Stackstorm ST2AI | 4/9/2026 | 4/9/2026 | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manipulation of the argument api_key_api.user leads to improper privilege management. The attack may be performed from… | |
| Aplazada | Baja (2.1) | 0.43% | — | Stackstorm ST2AI | 4/9/2026 | 8/9/2026 | A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC backend. This manipulation of the argument User causes improper privilege… | |
| Aplazada | Media (5.3) | 0.34% | — | Brainstormforce SureformsAI | 3/9/2026 | 7/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects SureForms: from n/a through 2.12.5. | |
| Aplazada | Alta (8.8) | 0.56% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's workstation when the exported CSV file is… | |
| Aplazada | Alta (7.5) | 0.58% | — | Brainstormforce SureformsAI | 18/8/2026 | 3/9/2026 | The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Brainstormforce Convert PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions. |