Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.63% | — | Sipeed PicoclawAI | 19/7/2026 | 21/7/2026 | A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication bypass using alternate channel. The attack… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sipeed PicoclawAI | 18/7/2026 | 20/7/2026 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.41% | — | Sipeed PicoclawAI | 18/7/2026 | 22/7/2026 | A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. The attack can be initiated remotely. The exploit has been made available to the… | |
| Aplazada | Baja (2.1) | 0.37% | — | Sipeed PicoclawAI | 18/7/2026 | 20/7/2026 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Baja (1.9) | 0.16% | — | Sipeed PicoclawAI | 18/7/2026 | 20/7/2026 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of the file pkg/agent/context.go. Such manipulation leads to inclusion of functionality from untrusted control sphere. The attack needs to be performed locally. The exploit has been disclosed publicly… | |
| Aplazada | Media (5.5) | 0.56% | — | Sipeed PicoclawAI | 18/7/2026 | 21/7/2026 | A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools/integration/web.go. This manipulation causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (1.9) | 0.12% | — | Sipeed PicoclawAI | 18/7/2026 | 22/7/2026 | A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun of the file pkg/agent/pipeline_execute.go. The manipulation of the argument cwe leads to time-of-check time-of-use. The attack must be carried out locally. The exploit is publicly available and might… | |
| Aplazada | Baja (2.1) | 0.24% | — | Sipeed PicoclawAI | 18/7/2026 | 20/7/2026 | A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file web/backend/api/auth.go. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch… | |
| Aplazada | Baja (2.1) | 0.40% | — | Sipeed PicoclawAI | 10/7/2026 | 10/7/2026 | A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pico.go. Performing a manipulation of the argument message.send results in missing authorization. It is possible to initiate the attack remotely. The exploit is now public… | |
| Aplazada | Media (5.5) | 0.54% | — | Sipeed PicoclawAI | 10/7/2026 | 10/7/2026 | A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. This affects the function IPAllowlist of the file web/backend/middleware/access_control.go of the component Launcher. Such manipulation leads to improper access controls. The attack may be performed from remote. The exploit has been disclosed… | |
| Aplazada | Baja (2.1) | 0.43% | — | Sipeed PicoclawAI | 10/7/2026 | 14/7/2026 | A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file pkg/tools/integration/web.go of the component Guarded Web Fetch Flow. The manipulation results in server-side request forgery. The attack can be executed remotely. The… | |
| Aplazada | Alta (7.3) | 1.8% | — | Sipeed PicoclawAI | 27/5/2026 | 17/6/2026 | picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a denylist of 8 regular expressions, but the denylist is incomplete. | |
| Analizada | Media (5.5) | 4.7% | — | Sipeed Picoclaw | 25/4/2026 | 17/6/2026 | A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher Management Plane. Performing a manipulation results in command injection. It is possible to initiate the attack remotely. The project was informed of the problem early… | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexSkipComment function in lex.c when called from LexScanGetToken. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceFP function in expression.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioBasePrintf function in cstdlib/string.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.34% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrcat function in cstdlib/string.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StdioOutPutc function in cstdlib/stdio.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the LexGetStringConstant function in lex.c when called from LexScanGetToken. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionAssign function in expression.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the StringStrncpy function in cstdlib/string.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceUnsignedInteger function in expression.c when called from ExpressionParseFunctionCall. | |
| Modificada | Media (5.5) | 0.33% | — | Picoc Project Picoc | 8/11/2022 | 17/6/2026 | PicoC Version 3.2.2 was discovered to contain a heap buffer overflow in the ExpressionCoerceInteger function in expression.c when called from ExpressionInfixOperator. | |
| Modificada | Media (5.5) | 0.32% | — | Picoc Project Picoc | 28/7/2022 | 17/6/2026 | PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c. | |
| Modificada | Alta (7.8) | 0.89% | — | Picoc Project Picoc | 13/9/2019 | 17/6/2026 | PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. |