Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.58%—Magentech FlashmartAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech FlashMart flashmart allows PHP Local File Inclusion.This issue affects FlashMart: from n/a through <= 2.0.15.
AplazadaAlta (8.1)0.58%—Magentech VictoAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Victo victo allows PHP Local File Inclusion.This issue affects Victo: from n/a through <= 1.4.16.
AnalizadaAlta (7.8)0.14%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaMedia (5.5)0.12%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service.
AnalizadaMedia (4.4)0.11%—Dell Device Management Agent4/3/202617/6/2026
Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access.
Pendiente de análisisMedia (6.5)1.6%💥 PoCModelscope Ms-agentAI2/3/202617/6/2026
A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input.
AnalizadaAlta (8.8)0.55%—Agentatech Agenta26/2/202617/6/2026
Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This…
AnalizadaCrítica (9.9)0.72%—Agentatech Agenta26/2/202617/6/2026
Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the `numpy` package as safe within the…
AnalizadaCrítica (10)1.0%💥 PoCAgentfront Enclave25/2/202617/6/2026
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1.
AplazadaCrítica (9.8)0.71%—Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AIAcronis Cyber Protect 15AI20/2/202617/6/2026
Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build…
AplazadaAlta (7.1)0.86%—EnvoyAIOpenpolicyagent OPA Envoy PluginAI19/2/202617/6/2026
opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority…
AnalizadaBaja (2.1)0.57%—Huggingface Smolagents18/2/202617/6/2026
A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public…
AnalizadaMedia (5.4)0.11%—Tenable Nessus Agent13/2/202617/6/2026
A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks.
AplazadaBaja (2.5)0.19%—Thales Safenet Agent FOR Windows LogonAI13/2/20263/9/2026
Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.
AplazadaMedia (6.2)0.39%—Cloudflare AgentsAI13/2/202617/6/2026
Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's…
AnalizadaMedia (5.1)0.18%—Flowring Agentflow10/2/202617/6/2026
AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
AnalizadaMedia (5.1)0.21%—Flowring Agentflow10/2/202617/6/2026
AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaAlta (8.7)0.46%—Flowring Agentflow10/2/202617/6/2026
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
AnalizadaCrítica (9.3)0.55%—Flowring Agentflow10/2/202617/6/2026
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.
AnalizadaCrítica (9.3)0.54%—Flowring Agentflow10/2/202617/6/2026
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.
AnalizadaMedia (6.4)0.23%—Agentfront Enclave6/2/202617/6/2026
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not cover the peculiar behavior or the vm…
AnalizadaAlta (8.3)0.13%—Eset Management Agent6/2/20263/9/2026
Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent
AnalizadaMedia (5.3)0.43%—Openmage Magento4/2/202617/6/2026
Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1.
AplazadaMedia (6.9)0.47%—Cloudflare Agents SDKAI3/2/202617/6/2026
Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK. The issue occurs because the `Message-ID` and `References` headers are parsed to derive the target agentName and agentId without proper validation or origin checks,…
AplazadaAlta (8.5)0.17%—HP Sure SenseAIDatto Windows AgentAI1/2/202617/6/2026
Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would…