Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1096 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.9) | 0.17% | — | Nousresearch Hermes-agentAI | 29/4/2026 | 17/6/2026 | A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. Upgrading… | |
| Aplazada | Media (5.5) | 0.69% | — | Nousresearch Hermes-agentAI | 29/4/2026 | 17/6/2026 | A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly… | |
| Aplazada | Alta (8.8) | 1.4% | — | Tubitak Bilgem Software Technologies Research Institute Pardus OS MY ComputerAI | 29/4/2026 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: from <=0.7.5 before 0.8.0. | |
| Aplazada | Baja (2.9) | 0.58% | — | Nousresearch Hermes-agentAI | 27/4/2026 | 17/6/2026 | A vulnerability was found in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/webhook.py of the component Webhooks Endpoint. The manipulation of the argument _INSECURE_NO_AUTH results in missing authentication. The attack can be launched remotely. A… | |
| Aplazada | Baja (2.9) | 0.58% | — | Nousresearch Hermes-agentAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in NousResearch hermes-agent 0.8.0. Affected by this vulnerability is the function _check_auth of the file gateway/platforms/api_server.py of the component API_SERVER_KEY Handler. The manipulation leads to improper authentication. The attack can be initiated remotely. The complexity of… | |
| Aplazada | Media (6.1) | 0.19% | — | MaharaAIElasticsearch7AI | 24/4/2026 | 17/6/2026 | Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter. | |
| Analizada | Alta (7.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in the FileBrowser API in AWS Research and Engineering Studio (RES) version 2024.10 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands on the cluster-manager EC2 instance via crafted input when using the FileBrowser functionality. To remediate this issue, users… | |
| Analizada | Alta (8.7) | 0.74% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized control of user-modifiable attributes in the session creation component in AWS Research and Engineering Studio (RES) prior to version 2026.03 could allow an authenticated remote user to escalate privileges, assume the virtual desktop host instance profile permissions, and interact with AWS resources and… | |
| Analizada | Alta (8.7) | 0.98% | — | Amazon Research AND Engineering Studio | 6/4/2026 | 24/7/2026 | Unsanitized input in an OS command in the virtual desktop session name handling in AWS Research and Engineering Studio (RES) version 2025.03 through 2025.12.01 might allow a remote authenticated actor to execute arbitrary commands as root on the virtual desktop host via a crafted session name. To remediate this issue,… | |
| Aplazada | Media (5.5) | 0.47% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A vulnerability was determined in assafelovic gpt-researcher up to 3.4.3. Affected is an unknown function of the component ws Endpoint. Executing a manipulation of the argument source_urls can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Media (5.5) | 0.65% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A vulnerability was found in assafelovic gpt-researcher up to 3.4.3. This impacts an unknown function of the component HTTP REST API Endpoint. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The project was… | |
| Aplazada | Media (5.5) | 0.52% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args leads to code injection. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.45% | — | Assafelovic Gpt-researcherAI | 6/4/2026 | 24/7/2026 | A flaw has been found in assafelovic gpt-researcher up to 3.4.3. The impacted element is an unknown function of the file backend/server/app.py of the component Report API. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used.… | |
| Aplazada | Baja (2.1) | 0.45% | — | Assafelovic GPT ResearcherAI | 6/4/2026 | 24/7/2026 | A weakness has been identified in assafelovic gpt-researcher up to 3.4.3. This issue affects some unknown processing of the file gpt_researcher/skills/researcher.py of the component WebSocket Interface. Executing a manipulation of the argument task can lead to cross site scripting. The attack may be launched remotely.… | |
| Aplazada | Media (6.9) | 0.16% | — | ECO SearchAI | 4/4/2026 | 21/7/2026 | Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiating a search operation. | |
| Aplazada | Media (6.9) | 0.17% | — | ONE SearchAI | 4/4/2026 | 21/7/2026 | One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled exception that crashes the… | |
| Aplazada | Baja (2.1) | 0.35% | — | Mixelpixx Google Research MCPAI | 3/4/2026 | 24/7/2026 | A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca613b736ab787bc926932f59cddc69457185a83. This issue affects the function extractContent of the file src/services/content-extractor.service.ts of the component Model Context Protocol Handler. The… | |
| Analizada | Media (6.5) | 0.36% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana. | |
| Analizada | Alta (8.1) | 0.33% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams. | |
| Analizada | Media (4.3) | 0.29% | — | Search-guard FLX | 31/3/2026 | 24/7/2026 | In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL. | |
| Analizada | Alta (8.6) | 0.19% | — | Kimtore Practical Music Search | 28/3/2026 | 7/10/2026 | PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via… | |
| Aplazada | Alta (7.1) | 0.25% | — | Eyecix JobsearchAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix JobSearch wp-jobsearch allows Reflected XSS.This issue affects JobSearch: from n/a through <= 3.2.0. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Eyecix Addon Jobsearch ChatAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows SQL Injection.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Eyecix Addon-jobsearch-chatAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eyecix Addon Jobsearch Chat addon-jobsearch-chat allows Reflected XSS.This issue affects Addon Jobsearch Chat: from n/a through <= 3.0. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Elated-themes Search AND GOAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n/a through <= 2.8. |