Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.35%—Microsoft Azure Connected Machine Agent9/9/20251/10/2026
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
AnalizadaCrítica (9.1)95%⚠ Explotación activa💥 ExploitAdobe CommerceAdobe Commerce B2BAdobe Magento9/9/202517/6/2026
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue…
AplazadaAlta (7.6)0.31%—Huggingface SmolagentsAI3/9/202525/9/2026
Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.
AnalizadaAlta (8.8)8.6%—Openagentplatform Dive3/9/202517/6/2026
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code Execution vulnerability triggered through a custom url value, `transport` in the JSON object. An attacker can exploit the vulnerability in the…
AplazadaAlta (7.8)0.13%—Acronis Cyber Protect Cloud AgentAI28/8/202525/9/2026
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40734.
AnalizadaMedia (6.9)0.11%—Pawelko Freebox V6 Agent28/8/202525/9/2026
Improper Certificate Validation in Checkmk Exchange plugin Freebox v6 agent allows attackers in MitM position to intercept traffic.
AplazadaAlta (7.3)0.14%—Acronis Cyber Protect Cloud AgentAI28/8/202517/6/2026
Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40296.
AplazadaMedia (5.5)0.46%—Request-filtering-agentAI25/8/202517/6/2026
request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Versions 1.x.x and earlier contain a vulnerability where HTTPS requests to 127.0.0.1 bypass IP address filtering, while HTTP requests are correctly blocked. This allows attackers to potentially access…
AnalizadaAlta (7.3)0.35%—Agent-zero21/8/202517/6/2026
Insecure permissions in Agent-Zero v0.8.* allow attackers to arbitrarily reset the system via unspecified vectors.
AnalizadaBaja (3.5)1.1%💥 ExploitAgent-zero21/8/202517/6/2026
An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.
AplazadaMedia (5.3)0.27%—Amazon ECS AgentAI14/8/202517/6/2026
We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the instances are in the same security group or if their security groups allow incoming connections that include the port where the server is hosted. This issue does…
AnalizadaMedia (5.3)0.66%—Adobe CommerceAdobe MagentoAdobe Commerce B2B12/8/202517/6/2026
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to modify…
AnalizadaMedia (5.9)0.40%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/8/202517/6/2026
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability by manipulating the timing between the…
AnalizadaAlta (8.7)0.64%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/8/202517/6/2026
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be exploited by a low-privileged attacker to inject malicious scripts into vulnerable form fields. A successful attacker can abuse this to…
AnalizadaAlta (7.5)0.60%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/8/202517/6/2026
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access.…
AnalizadaAlta (8.1)0.88%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/8/202517/6/2026
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in privilege escalation. A high-privileged attacker could trick a victim into executing unintended actions on a web application where…
AnalizadaAlta (7.5)0.56%—Adobe CommerceAdobe Commerce B2BAdobe Magento12/8/202517/6/2026
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing the application…
AplazadaBaja (2.1)1.8%—AgentuniverseAI7/8/202517/6/2026
A vulnerability was found in agentUniverse up to 0.0.18 and classified as critical. This issue affects the function StdioServerParameters of the component MCPSessionManager/MCPTool/MCPToolkit. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AplazadaBaja (2.1)1.8%—Skyworkai DeepresearchagentAI6/8/202517/6/2026
A vulnerability, which was classified as critical, was found in SkyworkAI DeepResearchAgent up to 08eb7f8eb9505d0094d75bb97ff7dacc3fa3bbf2. Affected is the function from_code/from_dict/from_mcp of the file src/tools/tools.py. The manipulation leads to os command injection. It is possible to launch the attack remotely.…
AnalizadaCrítica (10)25%—Huggingface Smolagents27/7/202517/6/2026
A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). The vulnerability stems from the local_python_executor.py module, which inadequately restricts Python code execution despite…
AplazadaCrítica (10)0.33%—Rolantis Information Technologies AgentisAI22/7/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis allows SQL Injection. This issue affects Agentis: before 4.32.
AplazadaMedia (6.1)0.19%—Rolantis Information Technologies AgentisAI22/7/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rolantis Information Technologies Agentis allows Reflected XSS, DOM-Based XSS. This issue affects Agentis: before 4.32.
AplazadaAlta (8.7)0.39%—Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI14/7/202517/6/2026
The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;…
AnalizadaAlta (7.5)0.96%—Microsoft Azure Monitor Agent8/7/202517/6/2026
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
AnalizadaMedia (5.1)0.35%—Agentejo Cockpit4/7/202517/6/2026
A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.11.4 is able to address…