Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.45% | — | MaxkbAIAmazon BedrockAIAmazon AWSAI | 21/9/2026 | 22/9/2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS… | |
| Pendiente de análisis | Alta (8.6) | 0.51% | — | Amazon BedrockAI | 4/8/2026 | 6/8/2026 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. | |
| Pendiente de análisis | Alta (8.4) | 0.73% | — | Amazon Bedrock Agent CoreAI | 23/7/2026 | 24/7/2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users should upgrade to… | |
| Pendiente de análisis | Media (5.7) | 0.38% | — | Amazon Bedrock Agentcore Python SDKAI | 16/7/2026 | 17/7/2026 | AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0 might allow a… | |
| Analizada | Crítica (9.8) | 0.97% | — | Microsoft Minecraft Bedrock Dedicated Server | 14/7/2026 | 22/7/2026 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (8.4) | 0.34% | — | Amazon Bedrock Agentcore Python SDKAI | 17/6/2026 | 22/6/2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK versions >= 1.1.3 and < 1.6.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To mitigate this issue, users… | |
| Analizada | Media (5.8) | 0.42% | — | Amazon Bedrock Agentcore Starter Toolkit | 16/3/2026 | 17/6/2026 | A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who… | |
| Modificada | Crítica (9.8) | 2.6% | — | Minecraft Bedrock Server | 28/3/2022 | 17/6/2026 | Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer). |