Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.9)0.63%—Sipeed PicoclawAI19/7/202621/7/2026
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack…
AplazadaBaja (2.1)0.37%—Sipeed PicoclawAI18/7/202620/7/2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit…
AplazadaBaja (2.1)0.41%—Sipeed PicoclawAI18/7/202622/7/2026
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been made available to the…
AplazadaBaja (2.1)0.37%—Sipeed PicoclawAI18/7/202620/7/2026
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the attack remotely. The exploit has been…
AplazadaBaja (1.9)0.16%—Sipeed PicoclawAI18/7/202620/7/2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally. The exploit has been disclosed publicly…
AplazadaMedia (5.5)0.56%—Sipeed PicoclawAI18/7/202621/7/2026
A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools/integration/web.go. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for…
AplazadaBaja (1.9)0.12%—Sipeed PicoclawAI18/7/202622/7/2026
A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might…
AplazadaBaja (2.1)0.24%—Sipeed PicoclawAI18/7/202620/7/2026
A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch…
AplazadaBaja (2.1)0.40%—Sipeed PicoclawAI10/7/202610/7/2026
A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the argument message.send results in missing authorization. It is possible to initiate the attack remotely. The exploit is now public…
AplazadaMedia (5.5)0.54%—Sipeed PicoclawAI10/7/202610/7/2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed…
AplazadaBaja (2.1)0.43%—Sipeed PicoclawAI10/7/202614/7/2026
A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The manipulation results in server-side request forgery. The attack can be executed remotely. The…
AplazadaAlta (7.3)1.8%—Sipeed PicoclawAI27/5/202617/6/2026
picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete.
AnalizadaMedia (5.5)4.7%—Sipeed Picoclaw25/4/202617/6/2026
A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early…
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called from LexScanGetToken.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceFP function in expression.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.34%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexGetStringConstant function in lex.c when called from LexScanGetToken.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionAssign function in expression.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in expression.c when called from ExpressionParseFunctionCall.
ModificadaMedia (5.5)0.33%—Picoc Project Picoc8/11/202217/6/2026
PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator.
ModificadaMedia (5.5)0.32%—Picoc Project Picoc28/7/202217/6/2026
PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.
ModificadaAlta (7.8)0.89%—Picoc Project Picoc13/9/201917/6/2026
PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.