Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6) | 0.45% | — | Hermes WebuiAI | 30/6/2026 | 14/7/2026 | Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but constructs the Session object without setting its profile in the /api/session/import handler, so the imported session is persisted with a null profile. Because a null profile is treated as the default profile… | |
| Aplazada | Media (6.9) | 0.52% | — | Hermes WebuiAI | 18/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and thread resources,… | |
| Aplazada | Alta (7.1) | 0.47% | — | Hermes WebuiAI | 17/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before serializing session data, enabling… | |
| Aplazada | Alta (7.1) | 0.47% | — | Hermes WebuiAI | 17/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to other profiles via GET… | |
| Aplazada | Crítica (9.1) | 0.82% | — | Hermes WebuiAI | 17/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/register/options and POST… | |
| Aplazada | Alta (8.6) | 0.50% | — | Hermes WebuiAI | 17/6/2026 | 17/9/2026 | Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scoped authorization checks and access… | |
| Aplazada | Media (6.8) | 0.15% | — | Hermes AgentAI | 17/6/2026 | 17/6/2026 | Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history,… | |
| Aplazada | Alta (8.7) | 0.81% | — | Hermes AgentAITiangolo FastapiAI | 17/6/2026 | 18/6/2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit… | |
| Aplazada | Crítica (9.2) | 0.73% | — | Hermes WebuiAI | 11/6/2026 | 14/7/2026 | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter to the settings API endpoint without any network origin restriction. Attackers on any reachable network can send a POST… | |
| Aplazada | Alta (8.7) | 1.3% | — | Hermes WebuiAI | 9/6/2026 | 23/7/2026 | Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration in a workspace repository's .git/config file. Attackers can exploit Git subprocess invocations in api/workspace_git.py… | |
| Aplazada | Media (4.3) | 0.10% | — | Hermes WebuiAI | 9/6/2026 | 23/7/2026 | Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete files outside the configured workspace boundary by replacing a validated path component with a symlink after validation… | |
| Aplazada | Media (6.3) | 0.51% | — | Hermes WebuiAI | 9/6/2026 | 23/7/2026 | Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-root path checks by exploiting an early return in the SSH/remote terminal profile workspace resolution logic within _remote_terminal_workspace_candidate(). Attackers can… | |
| Aplazada | Alta (7.1) | 0.47% | — | Hermes WebuiAI | 9/6/2026 | 23/7/2026 | Hermes WebUI before version 0.51.269 contains a profile isolation bypass vulnerability that allows authenticated users to access data belonging to other profiles by querying the session search endpoint without active-profile filtering. Attackers can send requests to the sessions search handler to retrieve session… | |
| Aplazada | Media (6.9) | 0.78% | — | Hermes WebuiAI | 9/6/2026 | 23/7/2026 | Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey options endpoint without completing assertion. Attackers can send unlimited POST requests to the authentication endpoint,… | |
| Aplazada | Baja (2.1) | 0.22% | — | Nousresearch Hermes-agentAI | 7/6/2026 | 23/7/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Alta (7.1) | 0.32% | — | Hermes WebuiAI | 4/6/2026 | 22/7/2026 | Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlinks that resolve to files or directories outside the designated workspace root. Attackers can exploit the workspace file and listing APIs, which resolve symlink targets… | |
| Aplazada | Baja (1.9) | 0.14% | — | Nousresearch Hermes-agentAI | 2/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential Pool Synchronization. The manipulation results in improper authentication. The attack must be… | |
| Aplazada | Media (5.5) | 0.37% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. This vulnerability affects the function _handle_webhook_request of the file gateway/platforms/feishu.py of the component Webhook Endpoint. Such manipulation leads to resource consumption. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.23% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. This affects the function _scan_memory_content of the file tools/memory_tool.py. This manipulation causes injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The… | |
| Aplazada | Baja (2.9) | 0.27% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.30. Affected by this issue is the function _sanitize_env_lines of the file hermes_cli/config.py. The manipulation results in injection. It is possible to launch the attack remotely. The attack requires a high level of complexity. The… | |
| Aplazada | Media (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Media (5.5) | 0.30% | — | Nousresearch Hermes-agentAI | 1/6/2026 | 22/7/2026 | A vulnerability was determined in NousResearch hermes-agent up to 2026.4.30. Affected is the function _serve_plugin_skill/skill_view of the file tools/skills_tool.py. Executing a manipulation can lead to injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.… | |
| Aplazada | Baja (1.9) | 0.32% | — | Nousresearch Hermes-agentAI | 24/5/2026 | 23/7/2026 | A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboard Interface. Performing a manipulation of the argument HERMES_ENABLE_PROJECT_PLUGINS results in incorrect comparison.… | |
| Aplazada | Media (5.5) | 0.64% | — | Nousresearch Hermes-agentAI | 24/5/2026 | 23/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly… | |
| Aplazada | Media (5.5) | 3.2% | — | Nousresearch Hermes-agentAI | 24/5/2026 | 23/7/2026 | A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The… |