Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

47 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.8)0.33%—Sinaptik AI Pandas-aiAI2/10/20266/10/2026
sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute.
AnalizadaAlta (7.3)0.30%—Gabrieleventuri Pandasai1/4/202617/6/2026
pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.
AplazadaMedia (5.5)0.67%—Gabrieleventuri PandasaiAI28/3/202617/6/2026
A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The…
AplazadaMedia (5.5)0.77%—Gabrieleventuri PandasaiAI28/3/202617/6/2026
A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for…
AplazadaMedia (5.5)0.41%—Sinaptik AI Pandasai LancedbAIGabrieleventuri PandasaiAI28/3/202617/6/2026
A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of…
ModificadaAlta (8.6)0.44%—Geopandas30/1/202617/6/2026
SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.
AplazadaAlta (8.5)0.37%💥 ExploitPandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI15/7/202517/6/2026
PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.…
AplazadaCrítica (9.8)1.2%—Gabrieleventuri PandasaiAI11/2/202517/6/2026
PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.
AnalizadaAlta (7.8)0.21%—Pandasecurity Panda Dome22/11/202417/6/2026
Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.8)0.29%—Pandasecurity Panda Dome22/11/202417/6/2026
Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaAlta (7.8)0.34%—Pandasecurity Panda Dome22/11/202417/6/2026
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaAlta (7.8)0.34%—Pandasecurity Panda Dome22/11/202417/6/2026
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
AnalizadaAlta (7.8)0.34%—Pandasecurity Panda Dome22/11/202417/6/2026
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
ModificadaCrítica (9.8)1.0%—Gabrieleventuri Pandasai22/1/202417/6/2026
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor…
ModificadaCrítica (9.8)1.5%—Gabrieleventuri Pandasai21/8/202317/6/2026
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.
ModificadaCrítica (9.8)1.4%—Gabrieleventuri Pandasai15/8/202317/6/2026
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
ModificadaAlta (7.8)0.26%—Pandasecurity Panda Adaptive Defense 360Pandasecurity Panda Devices Agent23/9/202117/6/2026
DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.
ModificadaCrítica (9.8)3.6%—Numfocus Pandas15/5/202017/6/2026
pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function…
ModificadaCrítica (9.8)3.5%—Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+223/5/201917/6/2026
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the…
ModificadaAlta (7.8)0.29%—Pandasecurity Panda Global Protection12/3/201817/6/2026
Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group.
ModificadaAlta (7.8)0.33%—Pandasecurity Panda Global Protection12/3/201817/6/2026
Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows local users to gain privileges via a malicious artefact.
ModificadaAlta (7.5)1.1%—Pandasecurity Panda Global Protection14/12/201717/6/2026
Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c04 \\.\PSMEMDriver DeviceIoControl request.
ModificadaAlta (7.5)1.1%—Pandasecurity Panda Global Protection14/12/201717/6/2026
Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c44 \\.\PSMEMDriver DeviceIoControl request.
ModificadaAlta (7.2)0.57%—Pandasecurity Panda AV PRO 2014Pandasecurity Panda Global Protection 2014Pandasecurity Panda Internet Security 201426/8/201417/6/2026
Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.
ModificadaAlta (7.2)0.37%—Pandasecurity Panda AV PRO 2014Pandasecurity Panda Global Protection 2014Pandasecurity Panda Gold ProtectionPandasecurity Panda Internet Security 201423/5/201417/6/2026
Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users to gain privileges via unspecified vectors.
Orbitaley — Vulnerabilidades