Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.39% | — | Nextlevelbuilder GoclawAI | 28/7/2026 | 28/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.Execute of the file goclaw/internal/http/tools_invoke.go of the component jq Handler. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 19/7/2026 | 20/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been published and may be used. | |
| Aplazada | Baja (2.1) | 0.46% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to server-side request forgery. The attack can be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 22/7/2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Baja (1.9) | 0.31% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit has been released to the public and may… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from remote. The exploit has been publicly… | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 18/7/2026 | 21/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is possible to be carried out remotely. The… | |
| Aplazada | Baja (2.1) | 0.42% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 14/7/2026 | A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This vulnerability affects the function handleNavigate of the file pkg/browser/tool.go. Such manipulation of the argument args.targetUrl leads to information disclosure. The attack may be performed from remote. The exploit is publicly… | |
| Aplazada | Baja (2.1) | 0.43% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 15/7/2026 | A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_bridge.go of the component ACP ToolBridge Workspace Handler. This manipulation causes path traversal. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.48% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 14/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file internal/tools/exec_approval.go. The manipulation results in incomplete blacklist. The attack can be executed remotely. The exploit has been made public and could be used. | |
| Aplazada | Baja (2.1) | 0.37% | — | Nextlevelbuilder GoclawAI | 14/7/2026 | 15/7/2026 | A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the file internal/tools/create_video_byteplus.go of the component invoke Endpoint. The manipulation of the argument output.video_url leads to server-side request forgery.… | |
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 5/7/2026 | 7/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. Such manipulation leads to incorrect authorization. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.40% | — | Nextlevelbuilder GoclawAI | 2/6/2026 | 22/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has… | |
| Aplazada | Baja (2.1) | 0.21% | — | Nextlevelbuilder GoclawAI | 2/6/2026 | 22/7/2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component Team Task Completion Handler. Executing a manipulation can lead to missing authorization. The attack may be… | |
| Aplazada | Baja (2) | 0.23% | — | Nextlevelbuilder GoclawAI | 2/6/2026 | 22/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of the component TTS Configuration Endpoint. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 1.3% | — | Nextlevelbuilder GoclawAI | 1/6/2026 | 22/7/2026 | A vulnerability was found in nextlevelbuilder GoClaw up to 3.11.3. This impacts the function FsBridge.WriteFile of the file internal/sandbox/fsbridge.go of the component write_file Tool. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.23% | — | Nextlevelbuilder GoclawAI | 1/6/2026 | 22/7/2026 | A vulnerability has been found in nextlevelbuilder GoClaw up to 3.11.3. This affects the function auth of the file internal/http/evolution_handlers.go. Such manipulation leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The project… | |
| Aplazada | Baja (2.1) | 0.21% | — | Nextlevelbuilder GoclawAI | 1/6/2026 | 22/7/2026 | A flaw has been found in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function handleSave of the file internal/http/tts_config.go of the component RoleAdmin Gateway. This manipulation causes improper privilege management. Remote exploitation of the attack is possible. The exploit has been… | |
| Aplazada | Media (5.5) | 0.51% | — | Nextlevelbuilder GoclawAINextlevelbuilder Goclaw LiteAI | 30/4/2026 | 17/6/2026 | A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9.0 mitigates this… |