Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.90%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/5/202628/8/2026
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application…
AnalizadaAlta (7.5)1.0%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/5/202628/8/2026
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application…
AnalizadaAlta (7.4)0.92%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/5/202628/8/2026
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read…
AnalizadaAlta (7.5)0.73%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/5/202628/8/2026
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.…
AnalizadaAlta (7.5)0.73%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/5/202628/8/2026
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access.…
AnalizadaMedia (6.5)0.64%—Microsoft Azure Monitor Agent12/5/202617/6/2026
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.30%—Microsoft Azure Connected Machine Agent12/5/202617/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.36%—Microsoft Azure Monitor Agent12/5/202618/6/2026
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AplazadaMedia (6.5)0.41%—Libwww-perl LWP UseragentAI12/5/202617/6/2026
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects. On a 3xx response, the redirect handler strips only Host and Cookie before issuing the follow-up request. Caller-supplied Authorization and Proxy-Authorization headers are sent unchanged to the…
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaMedia (5.5)0.69%—Inkeep AgentsAI11/5/202617/6/2026
A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. Performing a manipulation results in authentication bypass using alternate channel. The attack is possible to be carried…
AplazadaMedia (5.5)0.64%—Aiwaves-cn AgentsAIAiwaves-cn Cheshire CAT CoreAI11/5/202617/6/2026
A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/cat/looking_glass/stray_cat.py of the component cheshire_cat_core. This manipulation causes resource consumption. Remote…
AplazadaAlta (7.4)0.44%—Akamai Guardicore Platform AgentAIAkamai Zero Trust ClientAI8/5/202617/6/2026
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs()…
ModificadaAlta (8.6)0.43%—PraisonaiPraisonaiagents8/5/202617/6/2026
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.37 and praisonaiagents version 1.6.37, praisonaiagents resolves unresolved tool names against module globals and __main__ after it fails to match the declared tool list and the registry. With the default agent configuration, _perm_allow is None,…
AnalizadaAlta (7.7)0.57%—Praisonaiagents8/5/202617/6/2026
PraisonAI is a multi-agent teams system. Prior to version 1.6.32, the URL checking logic in PraisonAI has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. This issue has been patched in version 1.6.32.
ModificadaAlta (8.1)0.41%—PraisonaiPraisonaiagents8/5/202617/6/2026
PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass…
ModificadaAlta (8.5)0.18%—Watchguard Agent6/5/202610/8/2026
Uncontrolled Search Path Element vulnerability in WatchGuard Agent on Windows allows Using Malicious Files.
ModificadaAlta (8.5)0.16%—Watchguard Agent6/5/202610/8/2026
Use of Hard-coded Cryptographic Key vulnerability in WatchGuard Agent on Windows allows Inclusion of Code in Existing Process.
ModificadaAlta (7.3)0.15%—Watchguard Agent6/5/202610/8/2026
Incorrect permission assignment for a resource in the patch management component of the WatchGuard Agent on Windows allows an authenticated local user to elevate their privileges to NT AUTHORITY\\SYSTEM.
ModificadaAlta (7.1)0.35%—Watchguard Agent6/5/202610/8/2026
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.
ModificadaAlta (7.1)0.35%—Watchguard Agent6/5/202610/8/2026
Stack-based Buffer Overflow vulnerability in the WatchGuard Agent discovery service on Windows allows Overflow Buffers. An unauthenticated attacker on the same local network could exploit this vulnerability to crash the agent service.
AplazadaMedia (5.5)0.59%—Rtgs2017 NagaagentAI5/5/202617/6/2026
A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.py of the component Skills Endpoint. Such manipulation of the argument Name leads to path traversal. It is possible to launch the attack remotely. The exploit has been…
AplazadaMedia (4.6)0.30%—PPT AgentAI4/5/202617/6/2026
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary file write vulnerability via `save_generated_slides`. This issue has been patched via commit 418491a.
AplazadaAlta (8.6)0.21%—PPT AgentAI4/5/202617/6/2026
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtins in scope. This issue has been patched via commit 418491a.
AplazadaMedia (4.6)0.30%—PptagentAI4/5/202617/6/2026
PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This issue has been patched via commit 418491a.