Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3322 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | JobsearchAI | 17/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. | |
| Aplazada | Alta (7.4) | 0.32% | — | ARC SearchAI | 17/6/2026 | 17/6/2026 | Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing. | |
| Aplazada | Media (5.4) | 0.13% | — | Sony Optical Disc ArchiveAI | 16/6/2026 | 17/6/2026 | Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges. | |
| Analizada | Alta (8.1) | 0.25% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component. A remote attacker could exploit this heap buffer overflow vulnerability by providing a specially crafted MP3 file containing malformed ID3 tags. This incorrect length calculation during the… | |
| Analizada | Media (6.1) | 0.16% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 17/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 component. This heap buffer overflow vulnerability occurs when processing specially crafted MP3 files containing malformed ID3v2.3 COMM (Comment) tags. An attacker could exploit this by… | |
| Analizada | Media (5.6) | 0.21% | — | Gnome LocalsearchRedhat Enterprise Linux | 16/6/2026 | 18/6/2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds check in the `extract_performers_tags` function can lead to a heap buffer overflow. This vulnerability allows a remote attacker to cause a… | |
| Aplazada | Alta (8.2) | 0.37% | — | Maian SearchAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in AI Product Search for WooCommerce – Motive Commerce Search <= 1.38.2 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | Andreimarcu Linx-serverAI | 15/6/2026 | 17/6/2026 | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | |
| Aplazada | Alta (7.5) | 0.42% | — | Benbusby Whoogle SearchAI | 15/6/2026 | 17/6/2026 | An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request. | |
| Aplazada | Alta (8.5) | 2.5% | — | Tp-link Archer Ax12AITp-link Archer Ax17AITp-link Archer Ax18AITp-link Archer Ax1300AI | 10/6/2026 | 17/6/2026 | An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, authenticated attacker to execute arbitrary commands on the device by importing a specially crafted VPN client configuration file. The issue stems… | |
| Aplazada | Alta (8.1) | 0.75% | — | Maian SearchAIFrankenphpAI | 10/6/2026 | 17/6/2026 | FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the request path contains a non-ASCII byte. Two distinct flaws in that fallback let an attacker mislead FrankenPHP into… | |
| Aplazada | Media (5.1) | 0.47% | — | Typo3 CMSAITypo3 Indexed SearchAI | 9/6/2026 | 23/7/2026 | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in the search index without sanitization. When displayed in frontend search results via the Indexed Search plugin, these titles were rendered without proper output encoding, resulting in a Cross-Site… | |
| Aplazada | Alta (8.5) | 2.1% | — | Tp-link Archer Mr600AI | 8/6/2026 | 23/7/2026 | A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration… | |
| Aplazada | Baja (2.1) | 0.25% | — | Zilliztech Deep-searcherAI | 7/6/2026 | 23/7/2026 | A weakness has been identified in zilliztech deep-searcher up to 0.0.2. This affects the function CollectionRouter.invoke of the file deepsearcher/agent/collection_router.py. This manipulation of the argument kwargs causes improper access controls. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.22% | — | Nousresearch Hermes-agentAI | 7/6/2026 | 23/7/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Baja (1.9) | 0.14% | — | Nousresearch Hermes-agentAI | 2/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be… | |
| Aplazada | Media (5.5) | 0.37% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The… | |
| Aplazada | Baja (2.9) | 0.27% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires a high level of complexity. The… | |
| Aplazada | Media (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.… | |
| Aplazada | Alta (7.7) | 0.46% | — | ArcaneAI | 29/5/2026 | 25/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject… | |
| Aplazada | Alta (8.8) | 0.42% | — | ArcaneAI | 29/5/2026 | 22/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/environments/{id}/templates/variables endpoint, which writes the system-wide .env.global file used for variable substitution in every project's compose file, is missing an admin authorization check. Any… | |
| Aplazada | Alta (8.2) | 0.32% | — | ArcaneAI | 29/5/2026 | 17/6/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticated GET /api/app-images/logo endpoint reflects a user-supplied color query parameter into the body of an SVG document via strings.ReplaceAll with no escaping. The substitution lands inside a <style>… | |
| Aplazada | Media (6.3) | 0.36% | — | ArcaneAI | 29/5/2026 | 21/7/2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell command (sh -c "find … | while …") inside an Arcane helper container. The path sanitiser blocks ../… |