Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.8) | 0.10% | — | Veeam Agent FOR Microsoft WindowsAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows any local user to terminate arbitrary processes on the system. | |
| Pendiente de análisis | Media (4.1) | 0.12% | — | Veeam Agent FOR Microsoft WindowsAI | 7/10/2026 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows a low-privileged local user to make the agent write files to arbitrary locations when an administrator installs it. | |
| Pendiente de análisis | Media (5.7) | 0.23% | — | Amazon Bedrock Agentcore Starter ToolkitAI | 6/10/2026 | 7/10/2026 | Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in the same AWS account to cause the environment of a user importing a Bedrock Agent to issue arbitrary outbound requests… | |
| Pendiente de análisis | Alta (8.8) | 0.28% | — | Amazon Bedrock Agentcore Starter ToolkitAI | 6/10/2026 | 7/10/2026 | Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary code when a user imports and runs or deploys a Bedrock Agent, via crafted configuration values incorporated into generated… | |
| Pendiente de análisis | Crítica (9.6) | 1.9% | — | Progress Software Autonomous Rest Connector Genai AgentsAI | 6/10/2026 | 7/10/2026 | An OS command injection vulnerability in the shell-based temporary-file cleanup instructions in Progress Software Autonomous REST Connector GenAI Agents ARCGenAI-Generator version 2.0 allows an attacker who supplies a crafted Swagger/OpenAPI document to execute arbitrary commands on a developer's machine when a user… | |
| Aplazada | Alta (7.5) | 0.17% | — | Truelayer Magento 2 PluginAI | 6/10/2026 | 6/10/2026 | CVE-2026-103831: Insecure deserialization vulnerability in the Psr16CacheAdapter component of the TrueLayer Magento 2 Plugin, due to the use of PHP's native unserialize() function without restrictions on the classes allowed when retrieving data stored in the cache. An attacker who already has the ability to write… | |
| Aplazada | Crítica (9.8) | 0.94% | — | Modelscope AgentscopeAI | 2/10/2026 | 6/10/2026 | agentscope v1.0.20 contains code injection in execute_shell_command (src/agentscope/tool/_coding/_shell.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution. | |
| Pendiente de análisis | Media (6.9) | 0.14% | — | Amazon Security Agent MCP ServerAI | 1/10/2026 | 1/10/2026 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan… | |
| Pendiente de análisis | Media (4.8) | 0.15% | — | Fortra Boks Server AgentAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can… | |
| Aplazada | Crítica (9.8) | 0.27% | — | AgentgptAI | 30/9/2026 | 2/10/2026 | agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Aplazada | Crítica (9.8) | 0.33% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to… | |
| Aplazada | Alta (7.5) | 0.65% | — | Agent-zeroAI | 30/9/2026 | 1/10/2026 | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction. | |
| Aplazada | Sin puntuar | 0.24% | — | Agent-zeroAI | 30/9/2026 | 1/10/2026 | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. | |
| Aplazada | Alta (8.1) | 0.30% | — | Modelscope AgentscopeAI | 30/9/2026 | 2/10/2026 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | |
| Aplazada | Alta (8.1) | 0.32% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | |
| Aplazada | Alta (7.1) | 0.29% | — | Flowring AgentflowAI | 29/9/2026 | 30/9/2026 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
| Aplazada | Alta (8.7) | 0.23% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | |
| Aplazada | Baja (0.9) | 0.11% | — | Agentverus ScannerAI | 28/9/2026 | 1/10/2026 | A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a… | |
| Aplazada | Media (6.1) | 0.15% | — | Rolantis Information Technologies AgentisAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6. | |
| Aplazada | Media (6.5) | 0.21% | — | WSP MCP AI Agents ConnectorAI | 23/9/2026 | 23/9/2026 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Iflytek Astron-agentAI | 23/9/2026 | 23/9/2026 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading… | |
| Aplazada | Media (5.3) | 0.23% | — | Iflytek Astron-agentAI | 23/9/2026 | 25/9/2026 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is… |