Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.86% | — | Hermes AgentAI | 3/9/2026 | 8/9/2026 | Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled command. When a user opens the malicious… | |
| Aplazada | Media (5.3) | 0.51% | — | Nousresearch Hermes-agentAIElectronAI | 3/9/2026 | 3/9/2026 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing a manipulation results in allocation of resources. The attack may be initiated remotely.… | |
| Aplazada | Media (5.3) | 0.35% | — | Nousresearch Hermes-agentAI | 3/9/2026 | 5/9/2026 | A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The… | |
| Aplazada | Media (6.9) | 0.50% | — | Nousresearch Hermes-agentAI | 3/9/2026 | 3/9/2026 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session Management. This manipulation of the argument session_id causes authorization bypass. The attack can be initiated remotely. The vendor was contacted early about… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 1/9/2026 | 2/9/2026 | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulation results in uncontrolled memory allocation. It is possible to initiate the attack remotely. The exploit has been made… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 1/9/2026 | 2/9/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the… | |
| Aplazada | Baja (2.1) | 0.52% | — | Nousresearch Hermes-agentAI | 1/9/2026 | 4/9/2026 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried out remotely. The exploit has been… | |
| Aplazada | Crítica (9) | 0.34% | — | Hermes AgentAI | 28/8/2026 | 8/9/2026 | Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An attacker who compromises the upstream… | |
| Aplazada | Alta (7.6) | 0.43% | — | Hermes AgentAI | 28/8/2026 | 8/9/2026 | Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft malicious messages directing the agent's… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nousresearch Hermes-agentAI | 6/8/2026 | 12/8/2026 | A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed remotely. The exploit is now public and… | |
| Aplazada | Baja (2.1) | 0.37% | — | Nousresearch Hermes-agentAI | 6/8/2026 | 12/8/2026 | A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 4/8/2026 | 12/8/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/browser_tool.py of the component Browser Tooling. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.35% | — | Nousresearch Hermes-agentAI | 4/8/2026 | 12/8/2026 | A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of the component xAI Image Generation Provider. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been published… | |
| Aplazada | Baja (2.1) | 0.35% | — | Nousresearch Hermes-agentAI | 4/8/2026 | 12/8/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and… | |
| Aplazada | Baja (1.3) | 0.36% | — | Nousresearch Hermes-agentAI | 26/7/2026 | 27/7/2026 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls.… | |
| Aplazada | Baja (2) | 0.36% | — | Nousresearch Hermes-agentAI | 10/7/2026 | 10/7/2026 | A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function MatrixAdapter._markdown_to_html of the file gateway/platforms/matrix.py of the component Matrix Adapter. Such manipulation leads to cross site scripting. The attack can be executed remotely. The… | |
| Aplazada | Baja (2.1) | 0.48% | — | Nousresearch Hermes-agentAI | 6/7/2026 | 6/7/2026 | A vulnerability was determined in NousResearch hermes-agent 2026.5.29.2. The impacted element is the function skill_view of the file tools/skills_tool.py. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.77% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A vulnerability was detected in NousResearch hermes-agent up to 2026.5.16. This impacts the function extract_media of the file gateway/platforms/base.py of the component Live Webhook Endpoint. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit is now public and may… | |
| Aplazada | Baja (2.9) | 0.55% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 0.15.2. This affects the function DiscordAdapter._is_allowed_user of the file gateway/platforms/discord.py of the component Discord Platform Integration. Such manipulation leads to improper authentication. The attack can be launched… | |
| Aplazada | Baja (2.1) | 0.47% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 7/7/2026 | A weakness has been identified in NousResearch hermes-agent up to 2026.4.30. The impacted element is the function AIAgent.run_conversation of the file run_agent.py of the component HTTP API. This manipulation of the argument todos causes denial of service. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.38% | — | Nousresearch Hermes-agentAI | 4/7/2026 | 6/7/2026 | A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to launch the attack remotely. The exploit has been released to the public and may… | |
| Aplazada | Baja (1.3) | 0.37% | — | Nousresearch Hermes-agentAI | 3/7/2026 | 6/7/2026 | A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected is the function GatewayStreamConsumer._filter_and_accumulate of the file gateway/stream_consumer.py of the component Streaming Reasoning Tag Filter. The manipulation leads to improper handling of case sensitivity. The… | |
| Aplazada | Media (6.8) | 0.15% | — | Hermes AgentAI | 17/6/2026 | 17/6/2026 | Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644), exposing conversation history and HMAC secrets to local users. Attackers with local filesystem access can read these files directly to obtain sensitive data including conversation history,… | |
| Aplazada | Alta (8.7) | 0.81% | — | Hermes AgentAITiangolo FastapiAI | 17/6/2026 | 18/6/2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit… | |
| Aplazada | Baja (2.1) | 0.22% | — | Nousresearch Hermes-agentAI | 7/6/2026 | 23/7/2026 | A vulnerability has been found in NousResearch hermes-agent up to 0.12.0. This affects the function resolve_session_by_title of the file hermes_state.py of the component resume Endpoint. Such manipulation of the argument Title leads to authorization bypass. It is possible to launch the attack remotely. The exploit has… |