Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.37% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 25/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access. Exploitation of… | |
| Analizada | Baja (2.7) | 0.39% | — | Adobe Commerce B2BAdobe CommerceAdobe Magento | 25/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access.… | |
| Analizada | Media (5.1) | 0.73% | — | Xata Agent | 19/6/2025 | 17/6/2026 | A vulnerability was found in xataio Xata Agent up to 0.3.0. It has been classified as problematic. This affects the function GET of the file apps/dbagent/src/app/api/evals/route.ts. The manipulation of the argument passed leads to path traversal. Upgrading to version 0.3.1 is able to address this issue. The patch is… | |
| Analizada | Baja (2) | 0.70% | — | Xlang Openagents | 19/6/2025 | 17/6/2026 | A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is the function create_upload_file of the file backend/api/file.py. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Baja (2) | 0.52% | — | Openbmb Xagent | 19/6/2025 | 17/6/2026 | A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /conv/community. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.17% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Media (5.1) | 0.62% | — | Agent-zero | 17/6/2025 | 17/6/2026 | A vulnerability was found in frdel Agent-Zero up to 0.8.4. It has been rated as problematic. This issue affects the function image_get of the file /python/api/image_get.py. The manipulation of the argument path leads to path traversal. Upgrading to version 0.8.4.1 is able to address this issue. The identifier of the… | |
| Analizada | Alta (7.8) | 0.20% | — | Tenable Nessus Agent | 16/6/2025 | 17/6/2026 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could execute code with SYSTEM privilege. | |
| Analizada | Alta (7.8) | 0.18% | — | Tenable Nessus Agent | 13/6/2025 | 17/6/2026 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation. | |
| Analizada | Alta (7.8) | 0.17% | — | Tenable Nessus Agent | 13/6/2025 | 17/6/2026 | In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege. | |
| Analizada | Alta (8.4) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser… | |
| Analizada | Alta (8.1) | 0.57% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized elevated access.… | |
| Analizada | Alta (8.2) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access leading to a limited impact… | |
| Analizada | Media (5.3) | 0.47% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 10/6/2025 | 17/6/2026 | Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited write access. Exploitation of this… | |
| Aplazada | Alta (7.5) | 0.68% | — | Magentech RevoAI | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in magentech Revo revo allows PHP Local File Inclusion.This issue affects Revo: from n/a through <= 4.0.26. | |
| Analizada | Alta (7.8) | 0.32% | — | Action1 Agent | 6/6/2025 | 17/6/2026 | Action1 Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Action1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.… | |
| Analizada | Media (5.3) | 0.16% | — | Cisco Thousandeyes Endpoint Agent | 4/6/2025 | 17/6/2026 | Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on files that are in the local file system. An attacker could exploit… | |
| Aplazada | Media (6.7) | 0.13% | — | Acronis Cyber Protect Cloud AgentAI | 4/6/2025 | 17/6/2026 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 40077. | |
| Aplazada | Alta (7.5) | 0.37% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber ProtectAI | 4/6/2025 | 17/6/2026 | Denial of service due to improper handling of malformed input. The following products are affected: Acronis Cyber Protect Cloud Agent (Linux, macOS, Windows) before build 40077, Acronis Cyber Protect 17 (Linux, macOS, Windows) before build 41186. | |
| Aplazada | Alta (8.5) | 0.59% | 💥 Exploit | Broadcom Automic Automation Agent UnixAI | 20/5/2025 | 17/6/2026 | Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges. | |
| Aplazada | Media (5.4) | 0.15% | — | Qusupport LiveagentAI | 7/5/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in qusupport LiveAgent liveagent allows Cross Site Request Forgery.This issue affects LiveAgent: from n/a through <= 4.4.7. | |
| Analizada | Crítica (9.8) | 0.56% | — | Flowring Agentflow | 2/5/2025 | 17/6/2026 | Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack. | |
| Aplazada | Alta (7.4) | 0.53% | — | Openpolicyagent OPAAI | 1/5/2025 | 17/6/2026 | Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API for reading and writing documents. Requesting a virtual document through the Data API entails policy evaluation, where a Rego query containing a single data document… |