Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.90% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/5/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application… | |
| Analizada | Alta (7.5) | 1.0% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/5/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application… | |
| Analizada | Alta (7.4) | 0.92% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/5/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read… | |
| Analizada | Alta (7.5) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/5/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.… | |
| Analizada | Alta (7.5) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 12/5/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.… | |
| Analizada | Media (6.5) | 0.64% | — | Microsoft Azure Monitor Agent | 12/5/2026 | 17/6/2026 | Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.30% | — | Microsoft Azure Connected Machine Agent | 12/5/2026 | 17/6/2026 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Azure Monitor Agent | 12/5/2026 | 18/6/2026 | External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.41% | — | Libwww-perl LWP UseragentAI | 12/5/2026 | 17/6/2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (5.5) | 0.69% | — | Inkeep AgentsAI | 11/5/2026 | 17/6/2026 | A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in authentication bypass using alternate channel. The attack is possible to be carried… | |
| Aplazada | Media (5.5) | 0.64% | — | Aiwaves-cn AgentsAIAiwaves-cn Cheshire CAT CoreAI | 11/5/2026 | 17/6/2026 | A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/cat/looking_glass/stray_cat.py of the component cheshire_cat_core. This manipulation causes resource consumption. Remote… | |
| Aplazada | Alta (7.4) | 0.44% | — | Akamai Guardicore Platform AgentAIAkamai Zero Trust ClientAI | 8/5/2026 | 17/6/2026 | Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs()… | |
| Modificada | Alta (8.6) | 0.43% | — | PraisonaiPraisonaiagents | 8/5/2026 | 17/6/2026 | PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the registry. With the default agent configuration, _perm_allow is None,… | |
| Analizada | Alta (7.7) | 0.57% | — | Praisonaiagents | 8/5/2026 | 17/6/2026 | PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32. | |
| Modificada | Alta (8.1) | 0.41% | — | PraisonaiPraisonaiagents | 8/5/2026 | 17/6/2026 | PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass… | |
| Modificada | Alta (8.5) | 0.18% | — | Watchguard Agent | 6/5/2026 | 10/8/2026 | Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files. | |
| Modificada | Alta (8.5) | 0.16% | — | Watchguard Agent | 6/5/2026 | 10/8/2026 | Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process. | |
| Modificada | Alta (7.3) | 0.15% | — | Watchguard Agent | 6/5/2026 | 10/8/2026 | Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM. | |
| Modificada | Alta (7.1) | 0.35% | — | Watchguard Agent | 6/5/2026 | 10/8/2026 | Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service. | |
| Modificada | Alta (7.1) | 0.35% | — | Watchguard Agent | 6/5/2026 | 10/8/2026 | Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service. | |
| Aplazada | Media (5.5) | 0.59% | — | Rtgs2017 NagaagentAI | 5/5/2026 | 17/6/2026 | A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.py of the component Skills Endpoint. Such manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (4.6) | 0.30% | — | PPT AgentAI | 4/5/2026 | 17/6/2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary file write vulnerability via `save_generated_slides`. This issue has been patched via commit 418491a. | |
| Aplazada | Alta (8.6) | 0.21% | — | PPT AgentAI | 4/5/2026 | 17/6/2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a. | |
| Aplazada | Media (4.6) | 0.30% | — | PptagentAI | 4/5/2026 | 17/6/2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a. |