Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.53% | — | Heshengtao Super-agent-partyAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.51% | — | Heshengtao Super-agent-partyAI | 6/8/2026 | 12/8/2026 | A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack can be initiated remotely. The exploit… | |
| Aplazada | Alta (7.7) | 0.47% | — | PraisonaiagentsAI | 5/8/2026 | 8/9/2026 | PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulnerable to server-side request forgery. While it validates the initially supplied URL and blocks direct loopback and private destinations, its default httpx fallback uses… | |
| Aplazada | Alta (7.8) | 0.22% | — | PraisonaiAIPraisonaiagentsAI | 5/8/2026 | 8/9/2026 | PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's tools.py via a raw… | |
| Pendiente de análisis | Media (5) | 0.35% | — | Cisco Terminal Service AgentAI | 5/8/2026 | 6/8/2026 | A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least… | |
| Pendiente de análisis | Media (4.3) | 0.24% | — | RancherAIRancher Cattle-cluster-agentAIRancher DynamiclistenerAI | 5/8/2026 | 1/9/2026 | A denial-of-service vulnerability was identified in multiple TLS listeners in Rancher. Both the cattle-cluster-agent component running in downstream clusters and the Rancher server itself use the dynamiclistener library to serve TLS traffic. Without an effective CN filter configured, dynamiclistener automatically… | |
| Aplazada | Baja (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 4/8/2026 | 12/8/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.35% | — | Nousresearch Hermes-agentAI | 4/8/2026 | 12/8/2026 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Baja (2.1) | 0.35% | — | Nousresearch Hermes-agentAI | 4/8/2026 | 12/8/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and… | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Amazon Strands Agents ToolsAI | 3/8/2026 | 4/8/2026 | A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human consent gate. To remediate this issue,… | |
| Pendiente de análisis | Media (6.9) | 0.52% | — | Strands Agents ToolsAI | 31/7/2026 | 4/8/2026 | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to… | |
| Analizada | Alta (8.8) | 0.63% | 💥 PoC | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API. Attackers can craft a message… | |
| Analizada | Crítica (9.3) | 0.63% | 💥 PoC | Tugcantopaloglu Openclaw Agent Dashboard | 30/7/2026 | 3/9/2026 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the… | |
| Aplazada | Crítica (9.3) | 0.75% | — | Charx Ocpp AgentAI | 30/7/2026 | 31/7/2026 | Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. | |
| Pendiente de análisis | Crítica (9.3) | 0.22% | — | Agent Development KITAI | 29/7/2026 | 30/7/2026 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. This is possible because the framework did not verify if the… | |
| Pendiente de análisis | Alta (7.3) | 0.33% | — | IBM Observability With Instana AgentAIInstana CoreAI | 28/7/2026 | 30/7/2026 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API. | |
| Aplazada | Baja (1.3) | 0.36% | — | Nousresearch Hermes-agentAI | 26/7/2026 | 27/7/2026 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.… | |
| Pendiente de análisis | Alta (7.8) | 0.16% | — | Rapid7 InsightvmAIRapid7 NexposeAIRapid7 Insight AgentAI | 24/7/2026 | 30/7/2026 | Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight… | |
| Aplazada | Alta (7.2) | 0.78% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 30/7/2026 | In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell. | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Openstack Ironic Python AgentAI | 24/7/2026 | 9/9/2026 | In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it. | |
| Aplazada | Alta (8.8) | 0.39% | — | Zalando SkipperAIOpenpolicyagent OPAAI | 23/7/2026 | 30/7/2026 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty… | |
| Pendiente de análisis | Alta (8.4) | 0.73% | — | Amazon Bedrock Agent CoreAI | 23/7/2026 | 24/7/2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to… | |
| Aplazada | Baja (2.3) | 0.28% | — | AgentgptAI | 23/7/2026 | 23/7/2026 | AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The AgentCRUD.create_task and validate_task_count functions look… | |
| Aplazada | Alta (8.8) | 0.14% | — | Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI | 22/7/2026 | 22/7/2026 | The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory… | |
| Aplazada | Media (5.5) | 0.18% | — | PraisonaiAIPraisonaiagentsAI | 21/7/2026 | 21/7/2026 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, PraisonAI's direct-prompt CLI automatically expands `@url:` mentions in raw prompt text before agent execution begins. If a prompt contains `@url:<http-or-https-url>`, the CLI calls… |