Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.30% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction. | |
| Analizada | Alta (7.5) | 0.56% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of… | |
| Analizada | Media (4.3) | 0.35% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited… | |
| Analizada | Media (4.3) | 0.34% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited… | |
| Analizada | Baja (3.1) | 0.23% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and… | |
| Analizada | Media (5.5) | 0.24% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and… | |
| Analizada | Media (5.4) | 0.26% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires… | |
| Analizada | Media (4.8) | 0.27% | — | Adobe MagentoAdobe CommerceAdobe Commerce B2B | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user… | |
| Analizada | Alta (8.7) | 0.45% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analizada | Alta (7.5) | 0.60% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of… | |
| Analizada | Media (5.3) | 0.29% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view… | |
| Analizada | Media (4.3) | 0.26% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited… | |
| Analizada | Alta (8.1) | 0.38% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analizada | Media (5.3) | 0.52% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 11/3/2026 | 28/8/2026 | Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to… | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft ARC Enabled Servers Azure Connected Machine Agent | 10/3/2026 | 17/6/2026 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.48% | — | Fortinet Fortisoar Agent Communication Bridge | 10/3/2026 | 17/6/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the fortisoar user on a… | |
| Aplazada | Media (5.5) | 0.56% | — | Shy2593666979 AgentchatAI | 8/3/2026 | 17/6/2026 | A flaw has been found in Shy2593666979 AgentChat up to 2.3.0. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of the component User Endpoint. This manipulation of the argument user_id causes improper control of resource identifiers. It is possible to… | |
| Analizada | Media (6.5) | 0.25% | — | Lfprojects Agentgateway | 6/3/2026 | 17/6/2026 | Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environment. Prior to version 0.12.0, when converting MCP tools/call request to OpenAPI request, input path, query, and header values are not sanitized. This issue has been patched in version 0.12.0. | |
| Modificada | Alta (7.8) | 0.15% | — | Acronis AgentAcronis Cyber Protect | 6/3/2026 | 17/6/2026 | Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber Protect 17 (macOS) before build 41186, Acronis Cyber Protect Cloud Agent (macOS) before build 41124, Acronis True Image (macOS) before build 42902. | |
| Analizada | Alta (7.1) | 0.29% | — | Acronis AgentAcronis Cyber Protect | 6/3/2026 | 17/6/2026 | Default credentials set for local privileged user in Virtual Appliance. The following products are affected: Acronis Cyber Protect Cloud Agent (VMware) before build 36943, Acronis Cyber Protect 17 (VMware) before build 41186. | |
| Analizada | Media (4.4) | 0.16% | — | Acronis AgentAcronis Cyber Protect | 6/3/2026 | 17/6/2026 | Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40497, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | |
| Analizada | Alta (7.3) | 0.11% | — | Acronis Agent | 6/3/2026 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 41124. | |
| Analizada | Alta (7.1) | 0.10% | — | Acronis AgentAcronis Cyber Protect | 6/3/2026 | 17/6/2026 | Sensitive information disclosure and manipulation due to insufficient authorization checks. The following products are affected: Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186, Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124. | |
| Analizada | Media (4.4) | 0.12% | — | Acronis Agent | 6/3/2026 | 17/6/2026 | Credentials are not deleted from Acronis Agent after plan revocation. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 41124. |