Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.55% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper authentication. The attack can be launched… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 7/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (1.3) | 0.37% | — | Nousresearch Hermes-agentAI | 3/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to improper handling of case sensitivity. The… | |
| Analizada | Alta (7.8) | 0.17% | — | Dell Device Management Agent | 1/7/2026 | 6/7/2026 | Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (4.4) | 0.13% | — | Redhat Enterprise LinuxSpice-space Spice-vdagent | 29/6/2026 | 8/7/2026 | A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An… | |
| Analizada | Media (5.1) | 0.11% | — | Redhat Enterprise LinuxSpice-space Spice-vdagent | 29/6/2026 | 8/7/2026 | A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon to crash and resulting in a Denial of Service (DoS) for the virtual machine. This… | |
| Aplazada | Media (5.5) | 0.48% | — | Agentejo CockpitAI | 29/6/2026 | 29/6/2026 | A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Baja (1.3) | 0.34% | — | VoltagentAI | 28/6/2026 | 29/6/2026 | A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the component Memory REST API. Executing a manipulation of the argument conversationId can lead to improper authorization. The… | |
| Aplazada | Alta (8.5) | 0.15% | — | Expressupdate AgentAI | 26/6/2026 | 26/6/2026 | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges. | |
| Pendiente de análisis | Alta (8.4) | 0.34% | — | Amazon Bedrock Agentcore Python SDKAI | 17/6/2026 | 22/6/2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users… | |
| Aplazada | Media (6.8) | 0.15% | — | Hermes AgentAI | 17/6/2026 | 17/6/2026 | Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history,… | |
| Aplazada | Alta (8.7) | 0.81% | — | Hermes AgentAITiangolo FastapiAI | 17/6/2026 | 18/6/2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit… | |
| Aplazada | Crítica (9.4) | 0.57% | — | Openhuman Desktop AgentAI | 17/6/2026 | 10/8/2026 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | HP ONE AgentAI | 15/6/2026 | 18/6/2026 | Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial of service. HP is releasing software updates to mitigate these potential vulnerabilities. | |
| Aplazada | Alta (8.4) | 0.17% | — | IRU INC Kandji AgentAI | 15/6/2026 | 17/6/2026 | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality. | |
| Aplazada | Crítica (9.8) | 0.75% | — | Snmp4j-agentAI | 15/6/2026 | 17/6/2026 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. | |
| Aplazada | Alta (8.7) | 0.54% | — | Agenticmail MCPAI | 12/6/2026 | 17/6/2026 | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and… | |
| Pendiente de análisis | Crítica (9.3) | 6.5% | 💥 Exploit | Amasty Order AttributesAIMagentoAI | 12/6/2026 | 17/6/2026 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerability that allows unauthenticated attackers to write arbitrary files to the store's media directory by submitting files of any type or name to the upload endpoint without authentication, session… | |
| Aplazada | Crítica (9.9) | 1.4% | — | UID Enterprise AgentAI | 12/6/2026 | 17/6/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. | |
| Aplazada | Alta (7.8) | 0.12% | — | Checkpoint Identity AgentAI | 11/6/2026 | 17/6/2026 | A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an… | |
| Analizada | Media (5.9) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 10/6/2026 | 23/7/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Analizada | Media (4.4) | 0.10% | — | Paloaltonetworks Prisma Access Agent | 10/6/2026 | 23/7/2026 | A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel. This does not impact Prisma Access Agent on Windows, macOS, iOS, Android, or ChromeOS. | |
| Analizada | Crítica (9.6) | 0.43% | — | Kubev2v Assisted Migration Agent | 10/6/2026 | 17/6/2026 | A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately… | |
| Analizada | Alta (7.4) | 0.50% | — | Kubev2v Assisted Migration Agent | 10/6/2026 | 17/6/2026 | A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to… |