Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
1898 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | — | — | Amazon Security Agent MCP ServerAI | 1/10/2026 | 1/10/2026 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference value supplied to the diff scan… | |
| Pendiente de análisis | Media (4.8) | — | — | Fortra Boks Server AgentAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Server Agent contains a predictable password generation vulnerability in the adjoin utility. Machine-account passwords generated during Active Directory join or password renewal operations may have significantly less entropy than intended, making them more susceptible to prediction by an attacker who can… | |
| Aplazada | Sin puntuar | 0.19% | — | AgentgptAI | 30/9/2026 | 1/10/2026 | agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Aplazada | Crítica (9.8) | 0.20% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting forwards the model-produced tool call to… | |
| Aplazada | Alta (7.5) | 0.33% | — | Agent-zeroAI | 30/9/2026 | 1/10/2026 | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.__init__. The FileBrowser class initializes with the host root directory as the workspace, allowing the agent to access any file on the system without restriction. | |
| Aplazada | Sin puntuar | 0.33% | — | Agent-zeroAI | 30/9/2026 | 1/10/2026 | agent-zero 1.7, 1.8, 1.9, and 1.10 is vulnerable to Directory Traversal in python/helpers/file_browser.py:FileBrowser.save_file_b64. The save_file_b64 method accepts user-controlled file paths without normalization or validation, allowing path traversal attacks. | |
| Aplazada | Alta (8.1) | 0.39% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | modelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file. | |
| Aplazada | Alta (8.1) | 0.41% | — | Modelscope AgentscopeAI | 30/9/2026 | 1/10/2026 | modelscope Agentscope v1.0.18-v1.0.0 is vulnerable to Path Traversal in write_text_file. | |
| Pendiente de análisis | Alta (7.1) | 0.21% | — | Watchguard WgagentAI | 29/9/2026 | 30/9/2026 | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted… | |
| Pendiente de análisis | Alta (7.1) | 0.27% | — | Watchguard WgagentAI | 29/9/2026 | 30/9/2026 | A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted… | |
| Aplazada | Alta (7.1) | 0.29% | — | Flowring AgentflowAI | 29/9/2026 | 30/9/2026 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
| Aplazada | Alta (8.7) | 0.23% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | |
| Aplazada | Baja (0.9) | 0.11% | — | Agentverus ScannerAI | 28/9/2026 | 1/10/2026 | A vulnerability was found in agentverus agentverus-scanner up to 0.8.1. Affected by this vulnerability is the function isSecurityDefenseSkill of the file dist/scanner/analyzers/context.js. Performing a manipulation results in reliance on untrusted inputs in a security decision. The attack must be initiated from a… | |
| Aplazada | Media (6.1) | 0.15% | — | Rolantis Information Technologies AgentisAI | 28/9/2026 | 28/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes. This issue affects Agentis: from 4.44 before 4.6. | |
| Aplazada | Media (6.5) | 0.21% | — | WSP MCP AI Agents ConnectorAI | 23/9/2026 | 23/9/2026 | Contributor Broken Access Control in WSP MCP – AI Agents Connector <= 2.7.0 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Iflytek Astron-agentAI | 23/9/2026 | 23/9/2026 | A security vulnerability has been detected in iFlytek astron-agent up to 1.0.6. Affected by this vulnerability is the function UrlCheckTool.checkUrl of the component debugToolV2 API endpoint. The manipulation of the argument endPoint leads to server-side request forgery. The attack can be initiated remotely. Upgrading… | |
| Aplazada | Media (5.3) | 0.23% | — | Iflytek Astron-agentAI | 23/9/2026 | 25/9/2026 | A weakness has been identified in iFlytek astron-agent up to 1.0.7. Affected is an unknown function of the file console/backend/commons/src/main/resources/mapper/ChatBotMarketMapper.xml of the component getBotList API endpoint. Executing a manipulation of the argument sortDirection can lead to sql injection. It is… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Request-filtering-agentAI | 22/9/2026 | 25/9/2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (6.1) | 0.20% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 19/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data. | |
| Pendiente de análisis | Media (5.4) | 0.16% | — | IBM Common Licensing AgentAIIBM ARTAI | 18/9/2026 | 18/9/2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a… |