Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

1903 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)1.1%—Fosowl AgenticseekAI13/8/202624/9/2026
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated…
AnalizadaMedia (6)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
AnalizadaMedia (5.6)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
AnalizadaBaja (2.1)0.13%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome…
AnalizadaBaja (1.1)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome…
AnalizadaAlta (7.2)1.0%—Microsoft Azure Monitor Agent11/8/202613/8/2026
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
AplazadaAlta (8.7)0.83%—Openbmb XagentAI11/8/202624/9/2026
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check. Attackers can register an account without email…
AnalizadaCrítica (9.1)88%⚠ Explotación activa💥 ExploitAdobe CommerceAdobe Commerce B2BAdobe Magento11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
AnalizadaAlta (7.5)0.83%—Adobe Commerce B2BAdobe CommerceAdobe Magento11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
AnalizadaAlta (8.3)0.46%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited disruption to availability. Exploitation of this…
AnalizadaAlta (8.7)0.33%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially…
AnalizadaAlta (8.7)0.70%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially…
AnalizadaAlta (7.2)0.56%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction.
AnalizadaMedia (4.9)0.63%—Adobe CommerceAdobe MagentoAdobe Commerce B2B11/8/202625/9/2026
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user interaction.
AnalizadaCrítica (9.9)0.78%—Microsoft Azure SRE Agent7/8/20267/8/2026
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Pendiente de análisisMedia (4.2)0.21%—Cloudfoundry Bosh AgentAI6/8/202618/8/2026
Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with partially attacker-controlled body to any path ending in .network, and create any missing parent directories with mode 0777 via network Alias on Ubuntu. Affected versions: BOSH agent < v2.847.0…
Pendiente de análisisAlta (8.6)0.52%—Amazon Strands Agents ToolsAI6/8/202612/8/2026
Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit tool calls with a forged namespace…
AplazadaBaja (2.9)0.49%—Poco-ai Poco-agentAI6/8/202612/8/2026
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks…
AplazadaMedia (6.1)0.27%—Eonsr AEO AgentAI6/8/202626/8/2026
The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation before saving the post, allowing unauthenticated attackers to create administrator-attributed published posts containing arbitrary web scripts that execute in the…
AplazadaBaja (2.1)0.37%—Cosmicstack-labs Mercury-agentAI6/8/202612/8/2026
A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been…
AplazadaBaja (2.1)0.37%—Cosmicstack-labs Mercury-agentAI6/8/202612/8/2026
A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to initiate the attack remotely. The exploit…
AplazadaBaja (2.1)0.43%—Cosmicstack-labs Mercury-agentAI6/8/202612/8/2026
A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect privilege assignment. The attack may be…
AplazadaBaja (2.1)0.37%—Nousresearch Hermes-agentAI6/8/202612/8/2026
A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and…
AplazadaBaja (2.1)0.37%—Zhayujie CowagentAI6/8/202612/8/2026
A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The…
AplazadaBaja (2.1)0.37%—Nousresearch Hermes-agentAI6/8/202612/8/2026
A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been…