Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.47%—Modelscope AgentscopeAI20/4/202617/6/2026
A vulnerability was identified in modelscope agentscope up to 1.0.18. Affected by this issue is the function _parse_url/prepare_image/openai_audio_to_text of the file src/agentscope/tool/_multi_modality/_openai_tools.py of the component Cloud Metadata Endpoint. Such manipulation of the argument…
AplazadaMedia (5.5)0.52%—Modelscope AgentscopeAI20/4/202617/6/2026
A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shell_command of the file src/AgentScope/tool/_coding/_python.py. This manipulation causes code injection. The attack is possible to be carried out remotely. The exploit has…
AnalizadaAlta (8.5)0.19%—Rapid7 Insight Agent17/4/202617/6/2026
The Rapid7 Insight Agent (versions > 4.1.0.2) is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the agent service attempts to load an OpenSSL configuration file from a non-existent directory that is writable by standard users. By…
AplazadaCrítica (9.3)0.18%—Simopro Technology Winmatrix AgentAI16/4/202617/6/2026
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.
Pendiente de análisisMedia (5.5)0.13%—Cisco Thousandeyes Enterprise AgentAI15/4/202617/6/2026
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on files that are on the local file system of an affected…
AnalizadaAlta (8.6)0.59%—Agent-zero15/4/202617/6/2026
Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows users to define MCP servers using a JSON configuration containing arbitrary command and args values. These values are executed by the application when the configuration is applied…
AnalizadaAlta (7.8)2.5%—Microsoft Azure Monitor Agent14/4/202617/6/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.33%—Microsoft Azure Monitor Agent14/4/202617/6/2026
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.1)0.52%—PraisonaiPraisonaiagents14/4/202617/6/2026
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws WebSocket endpoint. The server…
AnalizadaCrítica (9.8)0.92%—PraisonaiPraisonaiagents14/4/202617/6/2026
PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the workflow engine is vulnerable to arbitrary command and code execution through untrusted YAML files. When praisonai workflow run <file.yaml> loads a YAML file with type: job, the JobWorkflowExecutor in…
AnalizadaAlta (8.4)0.23%—PraisonaiPraisonaiagents14/4/202617/6/2026
PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools()), and CLI…
Pendiente de análisisCrítica (9.3)2.2%💥 ExploitGoogle Agent Development KITAIGoogle Cloud RUNAIGoogle GKEAIPythonAI13/4/202617/6/2026
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance. This vulnerability…
AnalizadaMedia (4)0.15%—Paloaltonetworks Cortex XDR Agent13/4/20267/7/2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
AplazadaMedia (5.5)0.65%—Zhayujie Chatgpt-on-wechatAIZhayujie CowagentAI12/4/202617/6/2026
A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed…
AnalizadaAlta (7.1)0.40%—Praisonaiagents10/4/202617/6/2026
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() with follow_redirects=True and no host validation. An LLM agent tricked into crawling an internal URL can reach cloud metadata endpoints (169.254.169.254),…
AnalizadaMedia (6.8)0.10%—Rapid7 Insight Agent10/4/202617/6/2026
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated…
AnalizadaMedia (6.5)0.39%—Praisonaiagents9/4/202617/6/2026
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the execute_command function in shell_tools.py calls os.path.expandvars() on every command argument at line 64, manually re-implementing shell-level environment variable expansion despite using shell=False (line 88) for security. This allows exfiltration…
AnalizadaMedia (5.3)0.40%—Praisonaiagents9/4/202617/6/2026
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he list_files() tool in FileTools validates the directory parameter against workspace boundaries via _validate_path(), but passes the pattern parameter directly to Path.glob() without any validation. Since Python's Path.glob() supports .. path segments,…
AnalizadaMedia (6.5)0.38%—Praisonaiagents9/4/202617/6/2026
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praisonaiagents/tools/web_crawl_tools.py accepts arbitrary URLs from AI agents with zero validation. No scheme allowlisting, hostname/IP blocklisting, or private network checks are applied before fetching. This allows an…
AnalizadaAlta (7.5)0.33%—Praisonaiagents9/4/202617/6/2026
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, read_skill_file() in skill_tools.py allows reading arbitrary files from the filesystem by accepting an unrestricted skill_path parameter. Unlike file_tools.read_file which enforces workspace boundary confinement, and unlike run_skill_script which…
AnalizadaCrítica (9.3)0.34%—Praisonaiagents9/4/202617/6/2026
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, he memory hooks executor in praisonaiagents passes a user-controlled command string directly to subprocess.run() with shell=True at src/praisonai-agents/praisonaiagents/memory/hooks.py. No sanitization is performed and shell metacharacters are…
AnalizadaAlta (7.5)0.42%—Agentfront @frontmcp/adaptersAgentfront @frontmcp/sdkAgentfront FrontmcpFrontmcp Mcp-from-openapi8/4/202624/7/2026
FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in OpenAPI specifications without configuring any URL restrictions or custom resolvers. A malicious OpenAPI specification…
AnalizadaAlta (7.2)0.72%—Rapid7 Insight Agent8/4/202624/7/2026
An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically allow an attacker to achieve remote code execution as root via a crafted beacon response. Because the Agent uses mutual TLS (mTLS) to verify commands from the Rapid7 Platform, it is unlikely that the…
AplazadaBaja (2.1)0.45%—Imprvhub Mcp-browser-agentAI6/4/202624/7/2026
A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument request.params.name/request.params.arguments leads to server-side request forgery.…
AplazadaBaja (1.9)1.1%—Elgentos Magento2-dev-mcpAI5/4/202624/7/2026
A vulnerability was identified in elgentos magento2-dev-mcp up to 1.0.2. The affected element is the function executeMagerun2Command of the file src/index.ts. Such manipulation leads to os command injection. An attack has to be approached locally. The exploit is publicly available and might be used. The name of the…