Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.44% | — | AgentchatAI | 9/6/2026 | 23/7/2026 | An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via enumerating user IDs. | |
| Pendiente de análisis | Alta (8.8) | 0.34% | — | Agentcore CLIAI | 8/6/2026 | 23/7/2026 | Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS AgentCore Runtime under the imported agent's IAM execution role and on the local environment of another user in the same AWS… | |
| Aplazada | Baja (2.1) | 0.22% | — | Nousresearch Hermes-agentAI | 7/6/2026 | 23/7/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has… | |
| Pendiente de análisis | Alta (8.2) | 0.44% | — | Collibra AgentAI | 2/6/2026 | 22/7/2026 | Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints. | |
| Pendiente de análisis | Alta (7.5) | 0.40% | — | Collibra AgentAI | 2/6/2026 | 22/7/2026 | Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during ZIP extraction, this can allow an attacker to write files outside the intended extraction directory. | |
| Aplazada | Baja (1.9) | 0.14% | — | Nousresearch Hermes-agentAI | 2/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be… | |
| Aplazada | Alta (8.5) | 0.14% | — | Fujitsu Serverview AgentsAI | 1/6/2026 | 22/7/2026 | Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege. | |
| Aplazada | Alta (8.5) | 0.14% | — | Fujitsu Serverview Agents FOR WindowsAI | 1/6/2026 | 22/7/2026 | Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege. | |
| Aplazada | Media (5.5) | 0.37% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The… | |
| Aplazada | Baja (2.9) | 0.27% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires a high level of complexity. The… | |
| Aplazada | Media (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.… | |
| Pendiente de análisis | Alta (8.7) | 1.9% | — | Lakeside Systrak AgentAI | 28/5/2026 | 21/7/2026 | Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid… | |
| Aplazada | Alta (7.3) | 0.17% | 💥 PoC | Veeam Agent FOR Microsoft WindowsAI | 28/5/2026 | 23/9/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Gladinet Triofox Cloud Server Agent Access ServiceAI | 27/5/2026 | 17/6/2026 | Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache. | |
| Aplazada | Alta (7.5) | 0.46% | — | Triofox Server AgentAI | 27/5/2026 | 17/6/2026 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into the Triofox Server Agent Management Console). The returned NULL pointer is not checked before being dereferenced. | |
| Aplazada | Media (5.3) | 0.33% | — | Agent-zero Agent ZeroAI | 27/5/2026 | 14/7/2026 | Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the image_get API endpoint without Content-Security-Policy, X-Content-Type-Options, or Content-Disposition headers. Attackers… | |
| Aplazada | Alta (7.1) | 0.49% | — | Agent-zero Agent ZeroAI | 27/5/2026 | 14/7/2026 | Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, which relies solely on an extension allowlist while the path containment check is explicitly disabled. Attackers can… | |
| Analizada | Media (5.6) | 0.09% | — | Synology Active Backup FOR Business Agent | 27/5/2026 | 7/10/2026 | An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Activeprotect Agent | 27/5/2026 | 7/10/2026 | Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Aplazada | Alta (7.5) | 0.51% | — | Magentech SW CoreAI | 26/5/2026 | 24/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This issue affects SW Core: from n/a through 1.7.18. | |
| Aplazada | Baja (1.9) | 0.32% | — | Nousresearch Hermes-agentAI | 24/5/2026 | 23/7/2026 | A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison.… | |
| Aplazada | Media (5.5) | 0.64% | — | Nousresearch Hermes-agentAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 3.2% | — | Nousresearch Hermes-agentAI | 24/5/2026 | 23/7/2026 | A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The… |