Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)2.1%—Gh05tcrew Pentest AgentAI14/9/202614/9/2026
A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the function LocalRuntime.execute_command of the file runtime/runtime.py of the component LocalRuntime. Executing a manipulation can lead to os command injection. The attack may be performed from remote.…
AplazadaMedia (5.5)2.1%—Gh05tcrew PenstetagentAI14/9/202615/9/2026
A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerability affects the function run_task of the file interface/main.py of the component MCP HTTP Server. Performing a manipulation results in os command injection. The attack is possible to be carried out…
AplazadaAlta (8.1)0.16%—CrewaiAI13/9/202622/9/2026
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling ctypes.CDLL(None) loads the C library…
AplazadaMedia (6.5)0.35%—Crewai-toolsAI27/8/20268/9/2026
A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL commands via an unsanitized sql_query argument.
AplazadaCrítica (9.8)0.99%—Crewai-toolsAI27/8/20261/9/2026
A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.
AnalizadaAlta (8.3)0.52%—Crewai13/7/202617/9/2026
CrewAI before 1.15.1 contains a server-side request forgery vulnerability in the validate_url function that performs one-shot DNS resolution and blocklist checks before returning the original URL unchanged. Attackers can bypass the security filter by supplying URLs that redirect to internal addresses or use DNS…
AplazadaMedia (4.3)0.39%—Crew HRMAI9/7/20269/7/2026
The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers,…
AplazadaMedia (5.4)0.29%—Sekander Badsha Crew HRMAI2/6/202622/7/2026
Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Crew HRM: from n/a through 1.2.2.
AnalizadaCrítica (9.8)0.73%—Crewai30/3/202617/6/2026
CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that allows for RCE exploitation.
AnalizadaCrítica (9.8)0.49%—Crewai30/3/202617/6/2026
CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud services, facilitated by the RAG search tools not properly validating URLs provided at runtime.
AnalizadaAlta (7.5)0.60%—Crewai30/3/202617/6/2026
CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validation, enabling access to files on the server.
Pendiente de análisisCrítica (9.6)0.44%—CrewaiAISandboxpythonAI30/3/202617/6/2026
The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through arbitrary C function calling.
AplazadaAlta (7.6)0.32%—Lucidcrew WP Forum ServerAI27/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2.
AplazadaAlta (7.1)0.12%—Lucidcrew WP Forum ServerAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2.
AplazadaMedia (5.4)0.41%—Aims EcrewAI7/1/202517/6/2026
Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.
AplazadaCrítica (9)0.44%—Crew HRMAI19/8/202417/6/2026
Deserialization of Untrusted Data vulnerability in Crew HRM Crew HRM hr-management.This issue affects Crew HRM: from n/a through <= 1.1.1.
ModificadaAlta (8.8)1.3%—Fl3xx CrewFl3xx Dispatch20/9/202317/6/2026
Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
ModificadaMedia (6.5)0.78%—Fl3xx CrewFl3xx Dispatch20/9/202317/6/2026
An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter.
AnalizadaMedia (5.4)0.34%—Navblue N-ops & Crew1/9/202317/6/2026
NAVBLUE S.A.S N-Ops & Crew 22.5-rc.50 is vulnerable to Cross Site Scripting (XSS).
ModificadaAlta (7.2)1.3%—Paloaltonetworks Bridgecrew Checkov10/6/202117/6/2026
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.
ModificadaAlta (7.2)1.3%—Paloaltonetworks Bridgecrew Checkov20/4/202117/6/2026
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.
ModificadaAlta (7.5)3.7%—Sigil-ebook SigilFlightcrew Project FlightcrewCanonical Ubuntu Linux31/7/201917/6/2026
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
ModificadaAlta (7.8)1.6%—Flightcrew Project FlightcrewCanonical Ubuntu Linux4/7/201917/6/2026
FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
ModificadaMedia (5.5)1.0%—Flightcrew Project Flightcrew28/6/201917/6/2026
An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or GetRelativePathsToXhtmlDocuments() when a NULL pointer is passed to xc::XMLUri::isValidURI(). This affects third-party software (not Sigil) that uses FlightCrew as a library.
ModificadaCrítica (9.8)5.0%—Lucidcrew Pixie3/4/201717/6/2026
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.