Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1901 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Pendiente de análisis | Media (6.1) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… | |
| Pendiente de análisis | Crítica (10) | 0.18% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 21/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. | |
| Aplazada | Media (5.2) | 0.13% | — | Qnap QcalagentAI | 18/9/2026 | 28/9/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later | |
| Aplazada | Alta (8.1) | 0.49% | — | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.path value through path.resolve with process.cwd() and then uses the resulting… | |
| Aplazada | Alta (8.8) | 0.52% | — | AI Agent AutomationAI | 17/9/2026 | 24/9/2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and clearAgentMemory use a caller-supplied agentId or memory _id without verifying… | |
| Pendiente de análisis | Alta (8.7) | 0.64% | — | Amazon EKS Network Policy AgentAIAmazon VPC CNIAI | 16/9/2026 | 17/9/2026 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces via crafted pod and namespace names that produce pod identifier collisions.… | |
| Aplazada | Alta (8.7) | 1.3% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../' segments in requests to the… | |
| Aplazada | Crítica (9.2) | 0.32% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local subprocesses by MCPClientPool to achieve code… | |
| Aplazada | Alta (7.1) | 0.48% | — | Atomic-agents-stackAI | 15/9/2026 | 24/9/2026 | atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed budget limits in parallel batch operations. | |
| Pendiente de análisis | Alta (7.7) | 0.52% | — | Google Cloud Gemini Enterprise Agent Platform SDK FOR PythonAI | 15/9/2026 | 21/9/2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft. | |
| Aplazada | Crítica (9.4) | 0.64% | — | Praisonai AgentosAIPraisonaiAI | 15/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent… | |
| Aplazada | Alta (8.3) | 0.22% | — | PraisonaiagentsAIPraisonaiAI | 15/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication… | |
| Aplazada | Baja (2.1) | 0.37% | — | Cosmicstack-labs Mercury-agentAI | 14/9/2026 | 15/9/2026 | A flaw has been found in cosmicstack-labs mercury-agent up to 1.1.13. Affected by this vulnerability is the function githubRequest of the file src/utils/github.ts of the component GitHub API Handler. This manipulation of the argument path causes server-side request forgery. Remote exploitation of the attack is… | |
| Aplazada | Baja (2.1) | 0.55% | — | Cosmicstack-labs Mercury-agentAI | 14/9/2026 | 14/9/2026 | A vulnerability was detected in cosmicstack-labs mercury-agent up to 1.1.13. Affected is the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Execution. The manipulation results in incorrect behavior order: validate before canonicalize. The attack may be launched… | |
| Aplazada | Alta (8.2) | 0.46% | — | SkipperAIOpenpolicyagent Open Policy AgentAI | 14/9/2026 | 16/9/2026 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody filter in filters/openpolicyagent/openpolicyagent.go can allow an oversized declared Content-Length request to bypass a deny-on-presence Rego policy because ExtractHttpBodyOptionally leaves OPA with… | |
| Aplazada | Baja (2.1) | 0.39% | — | Cosmicstack-labs Mercury-agentAI | 14/9/2026 | 16/9/2026 | A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation leads to incorrect privilege assignment. The attack may be initiated remotely.… | |
| Aplazada | Baja (1.9) | 0.15% | — | Cosmicstack-labs Mercury-agentAI | 14/9/2026 | 14/9/2026 | A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manifest. Executing a manipulation can lead to information disclosure. The attack is… | |
| Aplazada | Baja (2.1) | 0.37% | — | Cosmicstack-labs Mercury AgentAI | 14/9/2026 | 15/9/2026 | A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Command Permission Check. Performing a manipulation results in improper… | |
| Pendiente de análisis | Media (6.2) | 0.12% | — | IBM Common Licensing AgentAIIBM ARTAI | 14/9/2026 | 16/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation controls and submit unauthorized values,… | |
| Aplazada | Alta (8.1) | 0.46% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended… | |
| Aplazada | Media (4.3) | 0.25% | — | PraisonaiagentsAI | 14/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praisonaiagents/server/server.py does not consult ServerConfig.auth_token before handling /publish, /events, or /info requests. A network client that can reach the server can broadcast arbitrary events to… | |
| Aplazada | Alta (8.5) | 0.38% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_blocked, which checks literal host encodings but does not resolve DNS names before scrape_page, crawl, extract_links, extract_text, or URL-mention fetches connect. An attacker-controlled hostname… |