Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.20% | — | Elastic Agent | 1/5/2025 | 17/6/2026 | Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection. An attacker requires local access and the ability to modify osqueryd configurations. | |
| Analizada | Alta (7.1) | 0.20% | — | Elastic AgentElastic Endpoint Security | 1/5/2025 | 17/6/2026 | Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by… | |
| Aplazada | Media (6.9) | 0.48% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper restriction of communication channel to intended endpoints. If exploited, a remote unauthenticated attacker may attempt to log in to an arbitrary host via Windows system where the product is running. | |
| Aplazada | Alta (7.1) | 0.69% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, an arbitrary file in the affected product may be obtained by a remote attacker who can log in to the product. | |
| Aplazada | Crítica (9.2) | 0.86% | — | Quick Agent V3AIQuick Agent V2AI | 28/4/2025 | 17/6/2026 | Quick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If exploited, arbitrary code may be executed by a remote unauthenticated attacker with the Windows system privilege where the product is running. | |
| Aplazada | Media (5.5) | 0.21% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 17AI | 24/4/2025 | 17/6/2026 | Denial of service due to allocation of resources without limits. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904, Acronis Cyber Protect 17 (Windows) before build 41186. | |
| Aplazada | Media (6.7) | 0.17% | — | Acronis Cyber Protect Cloud AgentAIAcronis Cyber Protect 16AI | 24/4/2025 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39904, Acronis Cyber Protect 16 (Windows) before build 39938. | |
| Analizada | Alta (7.3) | 0.13% | — | Dell Trusted Device Agent | 15/4/2025 | 17/6/2026 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.3) | 0.18% | — | Dell Trusted Device Agent | 15/4/2025 | 17/6/2026 | Dell Trusted Device, versions prior to 7.0.3.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (5.3) | 0.46% | — | Agent-zero | 14/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in frdel Agent-Zero 0.8.1.2. This vulnerability affects unknown code of the file /get_work_dir_files. The manipulation of the argument path leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (7.8) | 0.20% | — | Sophos Taegis Endpoint Agent | 11/4/2025 | 17/6/2026 | A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected. | |
| Analizada | Crítica (9.1) | 0.47% | — | Jenkins Ssh-agent | 10/4/2025 | 17/6/2026 | In jenkins/ssh-agent Docker images 6.11.1 and earlier, SSH host keys are generated on image creation for images based on Debian, causing all containers based on images of the same version use the same SSH host keys, allowing attackers able to insert themselves into the network path between the SSH client (typically… | |
| Analizada | Baja (2.7) | 0.48% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by… | |
| Analizada | Media (5.3) | 0.49% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Media (5.3) | 0.53% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this… | |
| Analizada | Media (4.3) | 0.57% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/4/2025 | 17/6/2026 | Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue… | |
| Aplazada | Media (6.3) | 0.15% | — | Watchguard Terminal Services AgentAI | 28/3/2025 | 8/8/2026 | The WatchGuard Terminal Services Agent on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. | |
| Aplazada | Media (6.3) | 0.13% | — | Acronis Cyber Protect Cloud AgentAI | 26/3/2025 | 17/6/2026 | Local privilege escalation due to a binary hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 39713. | |
| Aplazada | Media (6.5) | 0.34% | — | Z.com Bygmo GMO Font AgentAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Z.com byGMO GMO Font Agent gmo-font-agent allows Stored XSS.This issue affects GMO Font Agent: from n/a through <= 1.6. | |
| Aplazada | Alta (7.8) | 0.18% | — | Tenable Nessus AgentAI | 21/3/2025 | 17/6/2026 | When installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the non-default installation location. | |
| Analizada | Media (6.1) | 0.42% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to… | |
| Analizada | Crítica (9.1) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information… | |
| Analizada | Crítica (9.1) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to… | |
| Modificada | Alta (7.5) | 1.2% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Modelscope AgentscopeAI | 20/3/2025 | 17/6/2026 | A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, where serialized input is deserialized using dill.loads, enabling… |