Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

121 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.36%—4TU Researchdata DjehutyAI1/10/20262/10/2026
djehuty es un sistema de repositorio de datos de investigación desarrollado por 4TU.ResearchData. Antes de la versión 26.3.2, un atacante no autenticado puede inyectar SPARQL en las consultas de búsqueda/listado a través de tres parámetros distintos. Como las consultas afectadas son consultas de lectura (SELECT), esto…
AplazadaAlta (8.4)0.30%—4tu.researchdata DjehutyAI1/10/20266/10/2026
djehuty es un sistema de repositorio de datos de investigación desarrollado por 4TU.ResearchData. Antes de la versión 26.3.2, un depositante autenticado puede inyectar SPARQL arbitrario en una consulta que modifica el estado (DELETE/INSERT) suministrando un nombre de sesión manipulado, lo que le permite escribir (y…
AplazadaMedia (5.3)0.51%—Nousresearch Hermes-agentAIElectronAI3/9/20263/9/2026
Se ha encontrado una vulnerabilidad en NousResearch hermes-agent 0.18.0. Esta vulnerabilidad afecta a la función resourceBufferFromUrl del archivo apps/desktop/electron/main.ts del componente Electron Main Process. La manipulación da lugar a la asignación de recursos. El ataque puede iniciarse de forma remota. El…
AplazadaMedia (5.3)0.35%—Nousresearch Hermes-agentAI3/9/20265/9/2026
Se ha encontrado una vulnerabilidad en NousResearch hermes-agent 0.18.0. Afecta a la función fetchLinkTitle del archivo apps/desktop/src/app/artifacts/index.tsx del componente Link Title Fetch. Dicha manipulación del argumento url provoca una falsificación de solicitudes del lado del servidor (SSRF). El ataque puede…
AplazadaMedia (6.9)0.50%—Nousresearch Hermes-agentAI3/9/20263/9/2026
Se ha encontrado un fallo en NousResearch hermes-agent 0.18.0. Este problema afecta a la función _sess_nowait del archivo s71.py del componente Session Management. Esta manipulación del argumento session_id provoca una omisión de autorización. El ataque puede iniciarse de forma remota. Se contactó con el proveedor con…
AplazadaBaja (2.1)0.47%—Nousresearch Hermes-agentAI1/9/20262/9/2026
Se ha encontrado una vulnerabilidad en NousResearch hermes-agent hasta la 0.18.2. Esta vulnerabilidad afecta a la función list_tools del archivo tools/mcp_tool.py del componente MCP Tool. La realización de una manipulación da lugar a una asignación de memoria no controlada. Es posible iniciar el ataque de forma…
AplazadaBaja (2.1)0.47%—Nousresearch Hermes-agentAI1/9/20262/9/2026
Se ha encontrado una vulnerabilidad en NousResearch hermes-agent hasta la 0.18.2. Afecta a la función HermesACPAgent.prompt del archivo acp_adapter/session.py del componente ACP Prompt Workflow. Dicha manipulación provoca una denegación de servicio. El ataque puede realizarse de forma remota. El exploit se ha…
AplazadaBaja (2.1)0.52%—Nousresearch Hermes-agentAI1/9/20264/9/2026
Se ha encontrado un fallo en NousResearch hermes-agent 0.18.0. Este problema afecta a una funcionalidad desconocida del archivo gateway/platforms/api_server.py del componente Session Chat Interface. Esta manipulación provoca una denegación de servicio. El ataque puede llevarse a cabo de forma remota. El exploit se ha…
AplazadaCrítica (9.8)0.89%—Gpt-researcherAI27/8/20269/9/2026
Una vulnerabilidad en el endpoint WebSocket de gpt-researcher v0.14.7 y anteriores permite a un atacante remoto no autenticado lograr la ejecución de código mediante configuraciones maliciosas de Model Context Protocol.
AplazadaAlta (8.4)0.40%—Fujitsu Research OnecompressionAI12/8/202624/9/2026
Fujitsu Research's OneCompression library before 1.2.1 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load with weights_only=False, invoking…
AplazadaBaja (2.1)0.37%—Nousresearch Hermes-agentAI6/8/202612/8/2026
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and…
AplazadaBaja (2.1)0.37%—Nousresearch Hermes-agentAI6/8/202612/8/2026
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been…
AplazadaBaja (2.1)0.38%—Nousresearch Hermes-agentAI4/8/202612/8/2026
A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been…
AplazadaBaja (2.1)0.35%—Nousresearch Hermes-agentAI4/8/202612/8/2026
A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published…
AplazadaBaja (2.1)0.35%—Nousresearch Hermes-agentAI4/8/202612/8/2026
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and…
AplazadaBaja (1.3)0.36%—Nousresearch Hermes-agentAI26/7/202627/7/2026
A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.…
AplazadaAlta (8.3)0.41%—Mcp-webresearchAI21/7/202623/7/2026
mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering private or reserved IP ranges. Attackers…
Pendiente de análisisCrítica (9.8)0.72%—Open Source GPT Researcher GPT ResearcherAI15/7/20266/10/2026
Un problema en Open Source GPT Researcher v3.3.7 permite a los atacantes ejecutar comandos arbitrarios en un sistema víctima mediante la interacción del usuario con una página HTML manipulada.
AplazadaMedia (6.4)0.26%—Buddyholis TablesearchAI10/7/202610/7/2026
The BuddyHolis TableSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘placeholder’ parameter in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and…
AplazadaBaja (2)0.36%—Nousresearch Hermes-agentAI10/7/202610/7/2026
A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The…
Pendiente de análisisAlta (7.1)0.57%—Amazon Research AND Engineering StudioAI7/7/20268/7/2026
AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual desktops and computing resources on AWS. Improper link resolution before file access issue (CWE-59) in the Auth.GetUserPrivateKey API. An authenticated remote user could read…
AplazadaBaja (2.1)0.48%—Nousresearch Hermes-agentAI6/7/20266/7/2026
A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be…
AplazadaMedia (5.5)0.77%💥 PoCNousresearch Hermes-agentAI4/7/20266/7/2026
A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may…
AplazadaBaja (2.9)0.55%—Nousresearch Hermes-agentAI4/7/20266/7/2026
A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper authentication. The attack can be launched…
AplazadaBaja (2.1)0.47%—Nousresearch Hermes-agentAI4/7/20267/7/2026
A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been…