Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1901 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.60% | — | PraisonaiAIPraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.59 and praisonaiagents 1.6.59, the unauthenticated POST /api/v1/runs Jobs API accepts attacker-controlled agent_yaml, and the approve field can mark execute_command as YAML-approved before @require_approval checks critical tools. This chain allows a… | |
| Aplazada | Crítica (9.8) | 0.90% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list… | |
| Aplazada | Media (6.5) | 0.56% | — | PraisonaiagentsAI | 14/9/2026 | 16/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime assembly of blocklisted dunder names and allows str.format or str.format_map to resolve dotted fields through C-level attribute access that bypasses _safe_getattr. This exposes class, qualified-name,… | |
| Aplazada | Media (6.5) | 0.43% | — | PraisonaiagentsAI | 14/9/2026 | 15/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the initial URL and lets requests.Session.get follow redirects automatically, so a public-looking URL can redirect to a loopback, private, link-local, or metadata address without revalidation. The… | |
| Aplazada | Alta (7.5) | 0.53% | — | PraisonaiagentsAI | 14/9/2026 | 30/9/2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts file-mention values and falls back from workspace-relative resolution to Path(file_path) without traversal, symlink, or workspace-boundary validation. Prompt input from users, bots, or workflows can… | |
| Aplazada | Media (5.5) | 2.1% | — | Gh05tcrew Pentest AgentAI | 14/9/2026 | 14/9/2026 | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote.… | |
| Aplazada | Media (5.5) | 2.1% | — | Gh05tcrew PenstetagentAI | 14/9/2026 | 15/9/2026 | A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The attack is possible to be carried out… | |
| Pendiente de análisis | Alta (8.7) | 0.27% | — | Google Cloud Gemini Enterprise Agent Platform APP BuilderAIGoogle Cloud PlatformAIGoogle Compute EngineAI | 11/9/2026 | 11/9/2026 | A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This vulnerability was patched on 01 June 2026. Users… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | HPE Icewall Federation AgentAIHPE Icewall ProxyAI | 11/9/2026 | 11/9/2026 | A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). | |
| Pendiente de análisis | Crítica (9.1) | 0.38% | — | IBM Common Licensing AgentAIIBM ARTAI | 10/9/2026 | 11/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header. | |
| Aplazada | Alta (8.4) | 0.87% | — | Tianxi AI Agent PC ApplicationAI | 10/9/2026 | 11/9/2026 | A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially crafted link that is handled by the application. | |
| Pendiente de análisis | Alta (8.5) | 0.66% | — | Amazon Systems Manager AgentAI | 10/9/2026 | 10/9/2026 | A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon Security Agent MCP ServerAI | 10/9/2026 | 10/9/2026 | A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is… | |
| Pendiente de análisis | Media (5.1) | 0.44% | — | Amazon Aws-agents-for-devsecopsAI | 10/9/2026 | 10/9/2026 | A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected. | |
| Pendiente de análisis | Media (4.3) | 0.10% | — | Paloaltonetworks Prisma Access AgentAI | 10/9/2026 | 10/9/2026 | An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected. | |
| Pendiente de análisis | Crítica (10) | 0.74% | — | Google Cloud Agent Development KITAIPythonAI | 9/9/2026 | 9/9/2026 | A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python (OSS), Cloud Run, and GKE environments where pytest is installed allows an unauthenticated remote attacker to execute arbitrary code using a crafted test session replay. | |
| Analizada | Alta (8.6) | 0.83% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (8.7) | 0.84% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 11/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this… | |
| Analizada | Alta (7.6) | 1.1% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 10/9/2026 | Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions,… | |
| Analizada | Alta (8.6) | 0.69% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (7.5) | 0.82% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 11/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | |
| Analizada | Alta (8.2) | 0.67% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 10/9/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe CommerceAdobe Commerce B2BAdobe Magento | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… | |
| Analizada | Crítica (9.3) | 0.74% | — | Adobe MagentoAdobe CommerceAdobe Commerce B2B | 8/9/2026 | 9/9/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining… |