Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.14% | — | BMC Control-m/agentsAI | 16/9/2025 | 17/6/2026 | Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password. | |
| Aplazada | Alta (7.6) | 0.31% | — | Huggingface SmolagentsAI | 3/9/2025 | 25/9/2026 | Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code. | |
| Analizada | Crítica (10) | 25% | — | Huggingface Smolagents | 27/7/2025 | 17/6/2026 | A sandbox escape vulnerability was identified in huggingface/smolagents version 1.14.0, allowing attackers to bypass the restricted execution environment and achieve remote code execution (RCE). The vulnerability stems from the local_python_executor.py module, which inadequately restricts Python code execution despite… | |
| Analizada | Baja (2) | 0.70% | — | Xlang Openagents | 19/6/2025 | 17/6/2026 | A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critical. Affected by this issue is the function create_upload_file of the file backend/api/file.py. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used.… | |
| Analizada | Media (6.1) | 0.42% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to… | |
| Analizada | Crítica (9.1) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information… | |
| Analizada | Crítica (9.1) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to… | |
| Modificada | Alta (7.5) | 1.2% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint. | |
| Aplazada | Crítica (9.8) | 1.8% | — | Modelscope AgentscopeAI | 20/3/2025 | 17/6/2026 | A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, where serialized input is deserialized using dill.loads, enabling… | |
| Analizada | Alta (8.8) | 1.0% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting the download_file method. This can lead to unauthorized access to sensitive information, including… | |
| Aplazada | Alta (8.8) | 0.23% | — | Modelscope AgentscopeAI | 20/3/2025 | 17/6/2026 | A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints,… | |
| Analizada | Crítica (9.8) | 0.29% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can lead to unauthorized data access,… | |
| Analizada | Alta (7.5) | 0.76% | — | Modelscope Agentscope | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server. | |
| Analizada | Alta (7.5) | 0.52% | — | Modelscope Agentscope | 10/2/2025 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the /load-workflow endpoint of modelscope/agentscope version v0.0.4. This vulnerability allows an attacker to read arbitrary files from the server, including sensitive files such as API keys, by manipulating the filename parameter. The issue arises due to improper… | |
| Analizada | Crítica (9.8) | 0.81% | — | Modelscope Agentscope | 4/11/2024 | 17/6/2026 | In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands. | |
| Aplazada | Alta (8.8) | 1.4% | — | Redhat Fence Agents Remediation OperatorAI | 12/8/2024 | 17/6/2026 | A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer access, can create a specially crafted… | |
| Aplazada | Crítica (9.1) | 0.51% | — | Xlang OpenagentsAI | 6/5/2024 | 17/6/2026 | In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (6.5) | 0.58% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | |
| Modificada | Alta (8.8) | 0.45% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Azure VM Agents | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock Java Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1 | |
| Modificada | Crítica (9.8) | 0.97% | — | Forgerock WEB Policy Agents | 28/2/2023 | 17/6/2026 | Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1 | |
| Modificada | Alta (8.8) | 0.91% | — | Jenkins WMI Windows Agents | 17/5/2022 | 17/6/2026 | Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in. | |
| Modificada | Alta (8.8) | 1.9% | — | Jenkins WMI Windows Agents | 17/5/2022 | 17/6/2026 | Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflow vulnerability that may allow users able to connect to a named pipe to execute commands on the Windows agent machine. |