Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

40.021 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisCrítica (9.3)0.59%——1/10/20261/10/2026
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to…
AplazadaCrítica (10)0.31%—Backupsheep Wordpress Backup PluginAI1/10/20261/10/2026
The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files…
AplazadaCrítica (9.1)0.45%💥 PoCLatepointAI1/10/20261/10/2026
The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not properly validate a value before running…
AplazadaCrítica (9.3)0.29%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaCrítica (9.3)0.27%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaCrítica (9.3)0.34%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized manipulation. This issue affects…
AplazadaCrítica (9.3)0.38%—Hitachi Coding Software SuiteAI1/10/20261/10/2026
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.
AplazadaCrítica (9.3)0.33%—Genian NAC Ztna Policy ServerAI1/10/20261/10/2026
Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions
Pendiente de análisisCrítica (9.4)0.76%—Asus RouterAI1/10/20262/10/2026
Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.
Pendiente de análisisCrítica (9.2)0.28%—ES Iperf3AI30/9/20261/10/2026
iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed in 3.22
Pendiente de análisisCrítica (9.1)0.29%—Meta Horizon OSAI30/9/20261/10/2026
Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to impersonate the com.oculus.vrshell package, as…
AplazadaCrítica (9.8)0.33%—Stitionai DevikaAI30/9/20262/10/2026
Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.
AplazadaCrítica (9.8)0.40%—Stitionai DevikaAI30/9/20261/10/2026
Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.
AplazadaCrítica (9.8)0.91%—DeeptutorAI30/9/20261/10/2026
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
AplazadaCrítica (9.8)0.14%—Dbgpt Db-gptAI30/9/20267/10/2026
DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
AplazadaCrítica (9.8)0.27%—AgentgptAI30/9/20262/10/2026
agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object.
AplazadaCrítica (9.8)0.33%—Dbgpt Db-gptAI30/9/20261/10/2026
In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.
AplazadaCrítica (9.1)0.73%—Dbgpt Db-gptAI30/9/20261/10/2026
DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
AplazadaCrítica (9.1)0.31%—Dbgpt Db-gptAI30/9/20267/10/2026
DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.
AplazadaCrítica (9.8)0.33%—BishengAI30/9/20262/10/2026
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.
AplazadaCrítica (9.1)0.65%—BishengAI30/9/20261/10/2026
bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).
AplazadaCrítica (9.8)0.50%—Apache CamelAI30/9/20262/10/2026
In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.
AplazadaCrítica (9.8)0.40%—Apache CamelAI30/9/20262/10/2026
In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.
AplazadaCrítica (9.8)0.33%—Modelscope AgentscopeAI30/9/20261/10/2026
In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to…
AnalizadaCrítica (9.4)0.24%—Accellion Kiteworks30/9/20267/10/2026
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is…