Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.64%—Microsoft Azure Monitor Agent14/10/202517/6/2026
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.78%—Microsoft Azure Monitor Agent14/10/202517/6/2026
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.57%—Microsoft Azure Connected Machine Agent14/10/202517/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.56%—Microsoft Azure Connected Machine Agent14/10/202517/6/2026
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
AplazadaAlta (8.8)0.29%—Rolantis Information Technologies AgentisAI14/10/202517/6/2026
Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session Hijacking. This issue affects Agentis: before 4.44.
AplazadaAlta (7.3)0.33%💥 PoCZabbix AgentAIZabbix Agent 2AI3/10/202517/6/2026
In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL.
AplazadaAlta (8.8)0.38%—Codazon Magento ThemesAI1/10/202517/6/2026
A reflected cross-site scripted (XSS) vulnerability in Codazon Magento Themes v1.1.0.0 to v2.4.7 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload injected into the cat parameter.
AnalizadaMedia (6.5)0.43%—Coder Agentapi30/9/202517/6/2026
AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible to a client-side DNS rebinding attack when hosted over plain HTTP on localhost. An attacker can gain access to the /messages endpoint served by the Agent API. This allows for the unauthorized…
AplazadaMedia (5.9)0.22%—Modern Minds Magento 2 Wordpress IntegrationAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Modern Minds Magento 2 WordPress Integration m2wp allows Stored XSS.This issue affects Magento 2 WordPress Integration: from n/a through <= 1.4.2.1.
AplazadaAlta (7.8)0.15%—Cyrisma AgentAI16/9/202517/6/2026
A DLL hijacking vulnerability in CYRISMA Agent before 444 allows local users to escalate privileges and execute arbitrary code via multiple DLLs.
AplazadaAlta (8.4)0.37%—BMC Control-m AgentAI16/9/202517/6/2026
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases:
AnalizadaMedia (6.3)0.33%—BMC Control-m/agent16/9/202517/6/2026
A stack-based buffer overflow can be remotely triggered when formatting an error message in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following cases:
AnalizadaCrítica (9.3)0.16%—BMC Control-m/agent16/9/202517/6/2026
A buffer overflow in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions.
AnalizadaCrítica (9.3)0.18%—BMC Control-m/agent16/9/202517/6/2026
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100…
AplazadaMedia (6.9)0.39%—BMC Control-m AgentAIBMC Control-m ServerAI16/9/202517/6/2026
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default conditions (e.g. CVE-2025-55117 or…
AnalizadaCrítica (9.5)0.29%—BMC Control-m/agent16/9/202517/6/2026
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL…
AnalizadaAlta (7.6)0.22%—BMC Control-m/agent16/9/202517/6/2026
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent…
AnalizadaMedia (5.7)0.13%—BMC Control-m/agent16/9/202517/6/2026
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore…
AplazadaMedia (5.7)0.14%—BMC Control-m/agentsAI16/9/202517/6/2026
Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password.
AnalizadaCrítica (9.5)0.35%—BMC Control-m/agent16/9/202517/6/2026
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client…
AplazadaAlta (7.2)0.18%—Paloaltonetworks User-id Credential AgentAI12/9/202517/6/2026
—
AplazadaAlta (7.3)0.31%—Zabbix Agent 2AIZabbixAI12/9/202517/6/2026
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
AplazadaMedia (5.7)0.17%—Zabbix Agent 2AI12/9/202517/6/2026
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
AplazadaAlta (8.8)0.12%—Altiris Core Agent UpdaterAI11/9/202530/9/2026
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
AnalizadaAlta (7.8)0.37%—Microsoft Azure Connected Machine Agent9/9/202517/6/2026
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.