Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.58% | — | Magentech FlashmartAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech FlashMart flashmart allows PHP Local File Inclusion.This issue affects FlashMart: from n/a through <= 2.0.15. | |
| Aplazada | Alta (8.1) | 0.58% | — | Magentech VictoAI | 5/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Victo victo allows PHP Local File Inclusion.This issue affects Victo: from n/a through <= 1.4.16. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain an Improper Check for Unusual or Exceptional Conditions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service. | |
| Analizada | Media (4.4) | 0.11% | — | Dell Device Management Agent | 4/3/2026 | 17/6/2026 | Dell Device Management Agent (DDMA), versions prior to 26.02, contain a Plaintext Storage of Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized Access. | |
| Pendiente de análisis | Media (6.5) | 1.6% | 💥 PoC | Modelscope Ms-agentAI | 2/3/2026 | 17/6/2026 | A command injection vulnerability in ModelScope's ms-agent versions v1.6.0rc1 and earlier exists, allowing an attacker to execute arbitrary operating system commands through crafted prompt-derived input. | |
| Analizada | Alta (8.8) | 0.55% | — | Agentatech Agenta | 26/2/2026 | 17/6/2026 | Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This… | |
| Analizada | Crítica (9.9) | 0.72% | — | Agentatech Agenta | 26/2/2026 | 17/6/2026 | Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability existed in Agenta's custom code evaluator. Agenta used RestrictedPython as a sandboxing mechanism for user-supplied evaluator code, but incorrectly whitelisted the `numpy` package as safe within the… | |
| Analizada | Crítica (10) | 1.0% | 💥 PoC | Agentfront Enclave | 25/2/2026 | 17/6/2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version 2.11.1. | |
| Aplazada | Crítica (9.8) | 0.71% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AIAcronis Cyber Protect 15AI | 20/2/2026 | 17/6/2026 | Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 39870, Acronis Cyber Protect 16 (Linux, macOS, Windows) before build 39938, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build… | |
| Aplazada | Alta (7.1) | 0.86% | — | EnvoyAIOpenpolicyagent OPA Envoy PluginAI | 19/2/2026 | 17/6/2026 | opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability in how the `input.parsed_path` field is constructed. HTTP request paths are treated as full URIs when parsed; interpreting leading path segments prefixed with double slashes (`//`) as authority… | |
| Analizada | Baja (2.1) | 0.57% | — | Huggingface Smolagents | 18/2/2026 | 17/6/2026 | A weakness has been identified in huggingface smolagents 1.24.0. Impacted is the function requests.get/requests.post of the component LocalPythonExecutor. Executing a manipulation can lead to server-side request forgery. It is possible to launch the attack remotely. The exploit has been made available to the public… | |
| Analizada | Media (5.4) | 0.11% | — | Tenable Nessus Agent | 13/2/2026 | 17/6/2026 | A vulnerability has been identified where weak file permissions in the Nessus Agent directory on Windows hosts could allow unauthorized access, potentially permitting Denial of Service (DoS) attacks. | |
| Aplazada | Baja (2.5) | 0.19% | — | Thales Safenet Agent FOR Windows LogonAI | 13/2/2026 | 3/9/2026 | Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2. | |
| Aplazada | Media (6.2) | 0.39% | — | Cloudflare AgentsAI | 13/2/2026 | 17/6/2026 | Summary A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the AI Playground's OAuth callback handler. The `error_description` query parameter was directly interpolated into an HTML script tag without proper escaping, allowing attackers to execute arbitrary JavaScript in the context of the victim's… | |
| Analizada | Media (5.1) | 0.18% | — | Flowring Agentflow | 10/2/2026 | 17/6/2026 | AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load. | |
| Analizada | Media (5.1) | 0.21% | — | Flowring Agentflow | 10/2/2026 | 17/6/2026 | AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Analizada | Alta (8.7) | 0.46% | — | Flowring Agentflow | 10/2/2026 | 17/6/2026 | Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Analizada | Crítica (9.3) | 0.55% | — | Flowring Agentflow | 10/2/2026 | 17/6/2026 | Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality. | |
| Analizada | Crítica (9.3) | 0.54% | — | Flowring Agentflow | 10/2/2026 | 17/6/2026 | Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user. | |
| Analizada | Media (6.4) | 0.23% | — | Agentfront Enclave | 6/2/2026 | 17/6/2026 | Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers of security in enclave-vm are insufficient: The AST sanitization can be bypassed with dynamic property accesses, the hardening of the error objects does not cover the peculiar behavior or the vm… | |
| Analizada | Alta (8.3) | 0.13% | — | Eset Management Agent | 6/2/2026 | 3/9/2026 | Local privilege escalation vulnerability via insecure temporary batch file execution in ESET Management Agent | |
| Analizada | Media (5.3) | 0.43% | — | Openmage Magento | 4/2/2026 | 17/6/2026 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Prior to version 20.16.1, the admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations. This issue has been patched in version 20.16.1. | |
| Aplazada | Media (6.9) | 0.47% | — | Cloudflare Agents SDKAI | 3/2/2026 | 17/6/2026 | Summary An Insecure Direct Object Reference has been found to exist in `createHeaderBasedEmailResolver()` function within the Cloudflare Agents SDK. The issue occurs because the `Message-ID` and `References` headers are parsed to derive the target agentName and agentId without proper validation or origin checks,… | |
| Aplazada | Alta (8.5) | 0.17% | — | HP Sure SenseAIDatto Windows AgentAI | 1/2/2026 | 17/6/2026 | Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe to inject malicious code that would… |