Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.9)0.13%—Kimi Agent SDKAI29/1/202617/6/2026
Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publish.js and ovsx-publish.js scripts pass filenames to execSync() as shell command strings. Prior to version 0.1.6, filenames containing shell metacharacters like $(cmd) could execute arbitrary commands.…
AplazadaAlta (7)0.10%—WSS AgentAI28/1/202617/6/2026
WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
AplazadaAlta (8.5)0.17%—HP Sure SenseAIDatto Windows AgentAI25/1/202617/6/2026
Deep Instinct Windows Agent 1.2.24.0 contains an unquoted service path vulnerability in the DeepNetworkService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepNetworkService.exe to inject malicious code that…
AplazadaCrítica (9.8)1.2%💥 PoCKalrav AI AgentAI24/1/202617/6/2026
The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may…
AplazadaAlta (8.1)0.47%—Magentech MaxshopAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech MaxShop sw_maxshop allows PHP Local File Inclusion.This issue affects MaxShop: from n/a through <= 3.6.20.
AplazadaAlta (8.4)0.16%—Fsas Technologies Serverview Agents FOR WindowsAI21/1/202617/6/2026
The installer of ServerView Agents for Windows provided by Fsas Technologies Inc. may insecurely load Dynamic Link Libraries. Arbitrary code may be executed with the administrator privilege when the installer is executed.
AplazadaMedia (4.2)0.13%—Oracle Planning AND Budgeting Cloud ServiceAIOracle HyperionAIOracle EPM AgentAI20/1/202617/6/2026
Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service…
AnalizadaAlta (8.8)7.2%—Openagentplatform Dive16/1/202617/6/2026
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0, crafted deeplink can install an attacker-controlled MCP server configuration without sufficient user confirmation and can lead to arbitrary local command execution on the victim’s machine. This…
AnalizadaAlta (8.5)0.26%—Brother Bragent16/1/202617/6/2026
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Brother\BRAgent\ to inject and execute malicious code with elevated system permissions.
AnalizadaCrítica (10)0.76%💥 PoCAgentfront Enclave14/1/202617/6/2026
Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.7.0, there is a critical sandbox escape vulnerability in enclave-vm that allows untrusted, sandboxed JavaScript code to execute arbitrary code in the host Node.js runtime. When a tool invocation fails, enclave-vm exposes a…
AnalizadaAlta (7.8)0.32%—Microsoft Azure Connected Machine Agent13/1/202617/6/2026
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AplazadaAlta (7.3)0.13%—Tenable Nessus AgentAI13/1/202617/6/2026
A vulnerability has been identified in the installation/uninstallation of the Nessus Agent Tray App on Windows Hosts which could lead to escalation of privileges.
AnalizadaCrítica (9.3)53%💥 PoCServicenow NOW Assist AI AgentsServicenow Virtual Agent API12/1/202617/6/2026
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a relevant security update to hosted instances…
AplazadaAlta (8.1)0.57%—Magentech Rozy - Flower ShopAI8/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Rozy - Flower Shop rozy allows PHP Local File Inclusion.This issue affects Rozy - Flower Shop: from n/a through <= 1.2.25.
AplazadaAlta (8.1)0.39%—Jwsthemes FreeagentAI5/1/20267/10/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes FreeAgent freeagent allows PHP Local File Inclusion.This issue affects FreeAgent: from n/a through <= 2.1.2.
AplazadaCrítica (10)1.1%—Huggingface SmolagentsAI23/12/202517/6/2026
Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face smolagents. Authentication is not required to exploit this vulnerability. The specific…
AplazadaMedia (6.5)0.12%—Identity Agent FOR Terminal ServicesAI22/12/202517/6/2026
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being printed in plaintext in Identity Agent for Terminal Services debug files.
AplazadaMedia (6.5)0.12%—Checkpoint Identity AgentAI22/12/202517/6/2026
An authenticated local user can obtain information that allows claiming security policy rules of another user due to sensitive information being accessible in the Windows Registry keys for Check Point Identity Agent running on a Terminal Server.
AnalizadaCrítica (9.6)0.57%—Openagentplatform Dive19/12/202517/6/2026
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) vulnerability exists in versions prior to 0.11.1 in the Mermaid diagram rendering component. The application allows the execution of arbitrary JavaScript via…
AplazadaAlta (8.8)0.36%—Jthemes Sale Immigration LAW Visa Services Support Migration Agent ConsultingAI18/12/20255/10/2026
Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escalation.This issue affects Sale! Immigration law, Visa services support, Migration Agent Consulting: from n/a through <= 1.5.8.
AplazadaMedia (6.2)0.10%—Fortra Core Privileged Access ManagerAIFortra Boks Server AgentAI16/12/202517/6/2026
Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the selection of weak password hash algorithms. This issue affects BoKS Server Agent 9.0 instances that support yescrypt and are running in a BoKS 8.1 domain.
AnalizadaAlta (7.5)0.43%—Dynatrace Oneagent15/12/202517/6/2026
An issue was discovered in Dynatrace OneAgent before 1.325.47. When attempting to access a remote network share from a machine where OneAgent is installed and receiving a "STATUS_LOGON_FAILURE" error, the agent will retrieve every user token on the machine and repeatedly attempt to access the network share while…
AplazadaAlta (8.1)0.12%—Nxlog AgentAI14/12/20257/10/2026
NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
AnalizadaAlta (8.8)0.74%—Microsoft Azure Monitor Agent9/12/202517/6/2026
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
AplazadaAlta (7.8)0.15%—Akamai Guardicore Platform AgentAIOpensslAI3/12/202517/6/2026
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows…