Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.33% | — | Sinaptik AI Pandas-aiAI | 2/10/2026 | 6/10/2026 | sinaptik-ai pandas-ai 3.0.0 is vulnerable to Code Injection in CodeExecutor.execute. | |
| Analizada | Alta (7.3) | 0.30% | — | Gabrieleventuri Pandasai | 1/4/2026 | 17/6/2026 | pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component. | |
| Aplazada | Media (5.5) | 0.67% | — | Gabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.77% | — | Gabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal. The attack may be initiated remotely. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.41% | — | Sinaptik AI Pandasai LancedbAIGabrieleventuri PandasaiAI | 28/3/2026 | 17/6/2026 | A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of… | |
| Modificada | Alta (8.6) | 0.44% | — | Geopandas | 30/1/2026 | 17/6/2026 | SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database. | |
| Aplazada | Alta (8.5) | 0.37% | 💥 Exploit | Pandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI | 15/7/2025 | 17/6/2026 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Gabrieleventuri PandasaiAI | 11/2/2025 | 17/6/2026 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. | |
| Analizada | Alta (7.8) | 0.21% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.29% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome VPN DLL Hijacking Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Pandasecurity Panda Dome | 22/11/2024 | 17/6/2026 | Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Crítica (9.8) | 1.0% | — | Gabrieleventuri Pandasai | 22/1/2024 | 17/6/2026 | GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor… | |
| Modificada | Crítica (9.8) | 1.5% | — | Gabrieleventuri Pandasai | 21/8/2023 | 17/6/2026 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function. | |
| Modificada | Crítica (9.8) | 1.4% | — | Gabrieleventuri Pandasai | 15/8/2023 | 17/6/2026 | An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function. | |
| Modificada | Alta (7.8) | 0.26% | — | Pandasecurity Panda Adaptive Defense 360Pandasecurity Panda Devices Agent | 23/9/2021 | 17/6/2026 | DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file. | |
| Modificada | Crítica (9.8) | 3.6% | — | Numfocus Pandas | 15/5/2020 | 17/6/2026 | pandas through 1.0.3 can unserialize and execute commands from an untrusted file that is passed to the read_pickle() function, if __reduce__ makes an os.system call. NOTE: third parties dispute this issue because the read_pickle() function is documented as unsafe and it is the user's responsibility to use the function… | |
| Modificada | Crítica (9.8) | 3.5% | — | Pandasecurity Panda AntivirusPandasecurity Panda Antivirus PROPandasecurity Panda DomePandasecurity Panda Global Protection+2 | 23/5/2019 | 17/6/2026 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the… | |
| Modificada | Alta (7.8) | 0.29% | — | Pandasecurity Panda Global Protection | 12/3/2018 | 17/6/2026 | Panda Global Protection 17.0.1 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \.\pipe\PSANMSrvcPpal -- an "insecurely created named pipe." Ensures full access to Everyone users group. | |
| Modificada | Alta (7.8) | 0.33% | — | Pandasecurity Panda Global Protection | 12/3/2018 | 17/6/2026 | Unquoted Windows search path vulnerability in the panda_url_filtering service in Panda Global Protection 17.0.1 allows local users to gain privileges via a malicious artefact. | |
| Modificada | Alta (7.5) | 1.1% | — | Pandasecurity Panda Global Protection | 14/12/2017 | 17/6/2026 | Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c04 \\.\PSMEMDriver DeviceIoControl request. | |
| Modificada | Alta (7.5) | 1.1% | — | Pandasecurity Panda Global Protection | 14/12/2017 | 17/6/2026 | Panda Global Protection 17.0.1 allows a system crash via a 0xb3702c44 \\.\PSMEMDriver DeviceIoControl request. | |
| Modificada | Alta (7.2) | 0.57% | — | Pandasecurity Panda AV PRO 2014Pandasecurity Panda Global Protection 2014Pandasecurity Panda Internet Security 2014 | 26/8/2014 | 17/6/2026 | Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call. | |
| Modificada | Alta (7.2) | 0.37% | — | Pandasecurity Panda AV PRO 2014Pandasecurity Panda Global Protection 2014Pandasecurity Panda Gold ProtectionPandasecurity Panda Internet Security 2014 | 23/5/2014 | 17/6/2026 | Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users to gain privileges via unspecified vectors. |