Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1903 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.70% | — | Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events | 14/7/2026 | 28/8/2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially… | |
| Analizada | Alta (7.2) | 0.99% | — | Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events | 14/7/2026 | 28/8/2026 | Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to execute malicious SQL commands,… | |
| Analizada | Alta (8.6) | 0.76% | — | Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events | 14/7/2026 | 28/8/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to availability. Exploitation of this issue… | |
| Analizada | Alta (8.2) | 0.73% | — | Adobe CommerceAdobe Commerce B2BAdobe MagentoAdobe I/O Events | 14/7/2026 | 28/8/2026 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does not require user interaction. | |
| Modificada | Alta (8.8) | 0.50% | — | Microsoft Azure Connected Machine Agent | 14/7/2026 | 18/8/2026 | Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network. | |
| Analizada | Crítica (9.4) | 0.56% | — | Tenable Nessus Agent | 14/7/2026 | 25/8/2026 | A path traversal vulnerability in Tenable Agent 11.2.0 and 11.1.3 and lower allows a privileged attacker to write arbitrary files outside the intended plugin directory, potentially leading to remote code execution. | |
| Aplazada | Alta (7.5) | 1.1% | — | Openbmb XagentAI | 13/7/2026 | 13/7/2026 | OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The input parameter “filename” is user-controllable and is concatenated into the file path to be read without proper validation, leading to a directory traversal… | |
| Aplazada | Media (5.5) | 0.67% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 14/7/2026 | A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JWT Authentication Filter. This manipulation causes code injection. The attack may… | |
| Aplazada | Baja (2.1) | 2.0% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 13/7/2026 | A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy Script Handler. The manipulation results in os command injection. The attack can… | |
| Aplazada | Baja (2.1) | 2.7% | — | Soniccloudorg Sonic-agentAI | 12/7/2026 | 15/7/2026 | A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Media (6.9) | 0.37% | — | Praisonai AgentmailAI | 11/7/2026 | 13/7/2026 | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to… | |
| Aplazada | Alta (8.5) | 0.17% | — | PraisonaiagentsAI | 10/7/2026 | 14/7/2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (src/praisonai-agents/praisonaiagents/workflows/workflows.py). When a workflow step uses a string output_pydantic reference, the framework locates and imports a sibling… | |
| Aplazada | Media (6.9) | 0.41% | — | PraisonaiagentsAI | 10/7/2026 | 10/7/2026 | PraisonAI (praisonaiagents) before 1.6.78 contains a path traversal vulnerability in the FastContext feature (praisonaiagents.context.fast). FastContextAgent.execute_tool() prepends the configured workspace_path only for relative paths and neither rejects absolute paths nor canonicalizes joined paths before enforcing… | |
| Aplazada | Media (6.9) | 0.18% | — | PraisonaiagentsAI | 10/7/2026 | 10/7/2026 | PraisonAI (pip package praisonaiagents) before 1.6.78 automatically loads defaults from a project-local .praisonai/config.toml when constructing an Agent, and does not validate the defaults.output.output_file path. A repository-controlled config file can set output_file to an absolute or '..' traversal path; when the… | |
| Aplazada | Media (6.9) | 0.15% | — | Samsung SeagentserviceAI | 10/7/2026 | 10/7/2026 | Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information. | |
| Aplazada | Baja (2.1) | 0.37% | — | Zhayujie CowagentAI | 10/7/2026 | 10/7/2026 | A security flaw has been discovered in zhayujie CowAgent up to 2.1.0. The impacted element is an unknown function of the file channel/channel.py of the component Message Endpoint. The manipulation results in missing authorization. The attack may be launched remotely. The exploit has been released to the public and may… | |
| Aplazada | Media (5.3) | 0.56% | — | Zhayujie CowagentAI | 10/7/2026 | 10/7/2026 | A vulnerability was identified in zhayujie CowAgent up to 2.1.0. The affected element is the function _add_url/_add_package of the file agent/skills/service.py of the component Skill Installation Handler. The manipulation of the argument Name leads to path traversal. The attack may be initiated remotely. Upgrading to… | |
| Aplazada | Media (5.5) | 0.60% | — | Zhayujie CowagentAI | 10/7/2026 | 10/7/2026 | A vulnerability was determined in zhayujie CowAgent up to 2.1.1. Impacted is the function _build_image_content/_download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Executing a manipulation of the argument image can lead to server-side request forgery. The attack can be launched… | |
| Aplazada | Baja (2.1) | 0.42% | — | Zhayujie CowagentAI | 10/7/2026 | 14/7/2026 | A vulnerability was found in zhayujie CowAgent up to 2.1.0. This issue affects the function BrowserTool._do_navigate of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in information disclosure. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2) | 0.36% | — | Nousresearch Hermes-agentAI | 10/7/2026 | 10/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The… | |
| Analizada | Media (5.8) | 0.15% | — | Paloaltonetworks Prisma Access Agent | 9/7/2026 | 16/7/2026 | Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected. | |
| Analizada | Media (5.7) | 0.20% | — | Paloaltonetworks Prisma Access Agent | 9/7/2026 | 16/7/2026 | An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected. | |
| Pendiente de análisis | Alta (7) | 0.15% | — | Suse Rancher AI AgentAI | 6/7/2026 | 6/7/2026 | A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential sensitive data into logfiles, allowing local attackers to misuse respective gained data or credentials. | |
| Aplazada | Baja (2.1) | 0.48% | — | Nousresearch Hermes-agentAI | 6/7/2026 | 6/7/2026 | A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.77% | 💥 PoC | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may… |