Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.8)0.10%—Veeam Agent FOR Microsoft WindowsAI7/10/20267/10/2026
This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system.
Pendiente de análisisMedia (4.1)0.12%—Veeam Agent FOR Microsoft WindowsAI7/10/20267/10/2026
This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it.
Pendiente de análisisMedia (5.7)0.23%—Amazon Bedrock Agentcore Starter ToolkitAI6/10/20267/10/2026
Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests…
Pendiente de análisisAlta (8.8)0.28%—Amazon Bedrock Agentcore Starter ToolkitAI6/10/20267/10/2026
Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated…
Pendiente de análisisCrítica (9.6)1.9%—Progress Software Autonomous Rest Connector Genai AgentsAI6/10/20267/10/2026
An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user…
AplazadaAlta (7.5)0.17%—Truelayer Magento 2 PluginAI6/10/20266/10/2026
CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write…
AplazadaCrítica (9.8)0.94%—Modelscope AgentscopeAI2/10/20266/10/2026
agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Pendiente de análisisMedia (6.9)0.14%—Amazon Security Agent MCP ServerAI1/10/20261/10/2026
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan…
Pendiente de análisisMedia (4.8)0.15%—Fortra Boks Server AgentAI1/10/20261/10/2026
Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can…
AplazadaCrítica (9.8)0.27%—AgentgptAI30/9/20262/10/2026
agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AplazadaCrítica (9.8)0.33%—Modelscope AgentscopeAI30/9/20261/10/2026
In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to…
AplazadaAlta (7.5)0.65%—Agent-zeroAI30/9/20261/10/2026
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction.
AplazadaSin puntuar0.24%—Agent-zeroAI30/9/20261/10/2026
agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks.
AplazadaAlta (8.1)0.30%—Modelscope AgentscopeAI30/9/20262/10/2026
modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.
AplazadaAlta (8.1)0.32%—Modelscope AgentscopeAI30/9/20261/10/2026
modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file.
AplazadaAlta (7.1)0.29%—Flowring AgentflowAI29/9/202630/9/2026
Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.
AplazadaCrítica (9.3)0.27%—Flowring AgentflowAI29/9/202629/9/2026
Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file.
AplazadaAlta (8.7)0.23%—Flowring AgentflowAI29/9/202629/9/2026
Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.
AplazadaCrítica (9.3)0.28%—Flowring AgentflowAI29/9/202629/9/2026
SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.
AplazadaCrítica (9.3)0.34%—Flowring AgentflowAI29/9/202629/9/2026
SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.
AplazadaBaja (0.9)0.11%—Agentverus ScannerAI28/9/20261/10/2026
A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a…
AplazadaMedia (6.1)0.15%—Rolantis Information Technologies AgentisAI28/9/202628/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6.
AplazadaMedia (6.5)0.21%—WSP MCP AI Agents ConnectorAI23/9/202623/9/2026
Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions.
AplazadaMedia (5.3)0.30%—Iflytek Astron-agentAI23/9/202623/9/2026
A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading…
AplazadaMedia (5.3)0.23%—Iflytek Astron-agentAI23/9/202625/9/2026
A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is…