Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.12% | — | Zabbix AgentAIIBM AIXAI | 1/12/2025 | 17/6/2026 | Library loading on AIX Zabbix Agent builds can be hijacked by local users with write access to the /home/cecuser directory. | |
| Aplazada | Alta (7.6) | 0.29% | — | Nvidia Nemo Agent Toolkit UI FOR WEBAI | 25/11/2025 | 17/6/2026 | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service. | |
| Analizada | Crítica (9.8) | 0.54% | — | RSA Authentication Agent FOR Windows | 24/11/2025 | 17/6/2026 | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead… | |
| Analizada | Alta (7.8) | 0.40% | 💥 PoC | Ispyconnect Agent DVR | 18/11/2025 | 17/6/2026 | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands. | |
| Aplazada | Alta (7) | 0.11% | — | Datadog Linux Host AgentAI | 12/11/2025 | 17/6/2026 | The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog Linux Host Agent versions 7.65.0 through 7.70.2 exists due to insufficient permissions being set on the `opt/datadog-agent/python-scripts/__pycache__` directory during installation. Code in this… | |
| Analizada | Alta (7.3) | 0.33% | — | Microsoft Azure Monitor Agent | 11/11/2025 | 17/6/2026 | Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. | |
| Aplazada | Media (6.3) | 0.16% | — | Qualys Cloud AgentAI | 10/11/2025 | 7/10/2026 | The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environment. If the uninstall script is executed with elevated privileges (e.g., via sudo)… | |
| Analizada | Media (4.6) | 0.24% | — | Openmage Magento | 6/11/2025 | 17/6/2026 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin with direct database access or the admin notification feed source to inject malicious scripts into vulnerable… | |
| Aplazada | Crítica (9.5) | 0.83% | — | BMC Control-m AgentAI | 5/11/2025 | 17/6/2026 | The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar unauthorized actions when mutual SSL/TLS authentication is not enabled (i.e. in the default configuration). NOTE: | |
| Analizada | Media (5.3) | 0.22% | — | Salesforce Agentforce Vibes | 4/11/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0. | |
| Analizada | Media (5.3) | 0.24% | — | Salesforce Agentforce Vibes | 4/11/2025 | 17/6/2026 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0. | |
| Analizada | Media (6.5) | 0.21% | — | Salesforce Agentforce Vibes | 4/11/2025 | 17/6/2026 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0. | |
| Modificada | Alta (7.8) | 0.18% | — | Veeam Agent FOR Windows | 30/10/2025 | 7/10/2026 | This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation if a system administrator is tricked into restoring a malicious file. | |
| Analizada | Media (5.4) | 0.28% | 💥 PoC | Huggingface Smolagents | 22/10/2025 | 17/6/2026 | Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function located in src/smolagents/vision_web_browser.py. The function constructs an XPath query by directly concatenating user-supplied input into the XPath expression without proper sanitization or escaping.… | |
| Aplazada | Crítica (9.2) | 0.67% | — | Flowring AgentflowAI | 17/10/2025 | 17/6/2026 | Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability. | |
| Aplazada | Alta (8.7) | 0.83% | — | Flowring AgentflowAI | 17/10/2025 | 17/6/2026 | Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.8) | 0.21% | — | Fortinet Fortidlp Agent | 16/10/2025 | 17/6/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1 through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1… | |
| Analizada | Alta (7.8) | 0.21% | — | Fortinet Fortidlp Agent | 16/10/2025 | 17/6/2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy plugin for Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1 through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and… | |
| Analizada | Media (6) | 0.18% | — | Fortinet Fortidlp Agent | 16/10/2025 | 17/6/2026 | An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS and Windows 11.5.1 and 11.4.2 through 11.4.6 and 11.3.2 through 11.3.4 and 11.2.0 through 11.2.3 and 11.1.1. through 11.1.2 and 11.0.1 and 10.5.1 and 10.4.0, and 10.3.1… | |
| Analizada | Media (4.4) | 0.16% | — | Fortinet Fortidlp Agent | 16/10/2025 | 17/6/2026 | A insertion of sensitive information into log file in Fortinet FortiDLP 12.0.0 through 12.0.5, 11.5.1, 11.4.6, 11.4.5 allows attacker to information disclosure via re-using the enrollment code. | |
| Analizada | Media (6.5) | 0.43% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to elevated privileges that increase… | |
| Analizada | Media (4.8) | 0.27% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a… | |
| Analizada | Media (5.9) | 0.55% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploit depends on conditions beyond the… | |
| Analizada | Alta (8.1) | 0.60% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a stored Cross-Site Scripting (XSS) Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious… | |
| Analizada | Alta (8.1) | 0.60% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 14/10/2025 | 17/6/2026 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Incorrect Authorization vulnerability. A low-privileged attacker could leverage this vulnerability to bypass security measures and maintain unauthorized access. Exploitation of this issue does not… |