Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 2.1% | — | Gh05tcrew Pentest AgentAI | 14/9/2026 | 14/9/2026 | A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote.… | |
| Aplazada | Media (5.5) | 2.1% | — | Gh05tcrew PenstetagentAI | 14/9/2026 | 15/9/2026 | A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The attack is possible to be carried out… | |
| Aplazada | Alta (8.1) | 0.16% | — | CrewaiAI | 13/9/2026 | 22/9/2026 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library… | |
| Aplazada | Media (6.5) | 0.35% | — | Crewai-toolsAI | 27/8/2026 | 8/9/2026 | A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument. | |
| Aplazada | Crítica (9.8) | 0.99% | — | Crewai-toolsAI | 27/8/2026 | 1/9/2026 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument. | |
| Analizada | Alta (8.3) | 0.52% | — | Crewai | 13/7/2026 | 17/9/2026 | CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS… | |
| Aplazada | Media (4.3) | 0.39% | — | Crew HRMAI | 9/7/2026 | 9/7/2026 | The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.29% | — | Sekander Badsha Crew HRMAI | 2/6/2026 | 22/7/2026 | Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2. | |
| Analizada | Crítica (9.8) | 0.73% | — | Crewai | 30/3/2026 | 17/6/2026 | CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation. | |
| Analizada | Crítica (9.8) | 0.49% | — | Crewai | 30/3/2026 | 17/6/2026 | CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime. | |
| Analizada | Alta (7.5) | 0.60% | — | Crewai | 30/3/2026 | 17/6/2026 | CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server. | |
| Pendiente de análisis | Crítica (9.6) | 0.44% | — | CrewaiAISandboxpythonAI | 30/3/2026 | 17/6/2026 | The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling. | |
| Aplazada | Alta (7.6) | 0.32% | — | Lucidcrew WP Forum ServerAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.1) | 0.12% | — | Lucidcrew WP Forum ServerAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2. | |
| Aplazada | Media (5.4) | 0.41% | — | Aims EcrewAI | 7/1/2025 | 17/6/2026 | Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190. | |
| Aplazada | Crítica (9) | 0.44% | — | Crew HRMAI | 19/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1. | |
| Modificada | Alta (8.8) | 1.3% | — | Fl3xx CrewFl3xx Dispatch | 20/9/2023 | 17/6/2026 | Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component. | |
| Modificada | Media (6.5) | 0.78% | — | Fl3xx CrewFl3xx Dispatch | 20/9/2023 | 17/6/2026 | An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter. | |
| Analizada | Media (5.4) | 0.34% | — | Navblue N-ops & Crew | 1/9/2023 | 17/6/2026 | NAVBLUE S.A.S N-Ops & Crew 22.5-rc.50 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (7.2) | 1.3% | — | Paloaltonetworks Bridgecrew Checkov | 10/6/2021 | 17/6/2026 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted. | |
| Modificada | Alta (7.2) | 1.3% | — | Paloaltonetworks Bridgecrew Checkov | 20/4/2021 | 17/6/2026 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted. | |
| Modificada | Alta (7.5) | 3.7% | — | Sigil-ebook SigilFlightcrew Project FlightcrewCanonical Ubuntu Linux | 31/7/2019 | 17/6/2026 | Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. | |
| Modificada | Alta (7.8) | 1.6% | — | Flightcrew Project FlightcrewCanonical Ubuntu Linux | 4/7/2019 | 17/6/2026 | FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. | |
| Modificada | Media (5.5) | 1.0% | — | Flightcrew Project Flightcrew | 28/6/2019 | 17/6/2026 | An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library. | |
| Modificada | Crítica (9.8) | 5.0% | — | Lucidcrew Pixie | 3/4/2017 | 17/6/2026 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. |