Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. | |
| Pendiente de análisis | Alta (7.6) | 1.5% | — | Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | Bosch Configuration ManagerAI | 23/7/2026 | 1/10/2026 | Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information. | |
| Analizada | Alta (8.8) | 0.78% | 💥 PoC | Microsoft Configuration Manager 2503Microsoft Configuration Manager 2509Microsoft Configuration Manager 2603 | 14/7/2026 | 30/7/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (7.5) | 0.16% | — | Hitachi Configuration ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00. | |
| Analizada | Media (5.2) | 0.14% | 💥 PoC | Hitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager | 25/2/2026 | 17/6/2026 | Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before… | |
| Analizada | Media (6.7) | 0.35% | — | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 11/11/2025 | 17/6/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (4.8) | 3.3% | 💥 PoC | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 31/10/2025 | 17/6/2026 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. | |
| Modificada | Alta (8.8) | 0.37% | 💥 PoC | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 14/10/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. | |
| Modificada | Media (6.8) | 0.68% | 💥 PoC | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 14/10/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. | |
| Analizada | Alta (8) | 2.7% | 💥 PoC | Microsoft Configuration Manager 2503 | 8/7/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. | |
| Aplazada | Media (4.3) | 0.25% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+1 | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page. | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+2 | 10/12/2024 | 17/6/2026 | Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | |
| Analizada | Crítica (9.8) | 81% | ⚠ Explotación activa💥 PoC | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 8/10/2024 | 17/6/2026 | Microsoft Configuration Manager Remote Code Execution Vulnerability | |
| Modificada | Alta (8.6) | 47% | 💥 Exploit | Zohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+3 | 8/1/2024 | 17/6/2026 | A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability. | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Alta (8.8) | 2.1% | — | Solarwinds Network Configuration Manager | 9/11/2023 | 17/6/2026 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 | |
| Modificada | Alta (8.8) | 3.0% | — | Solarwinds Network Configuration Manager | 9/11/2023 | 17/6/2026 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226 | |
| Modificada | Media (4.9) | 0.44% | — | Solarwinds Network Configuration Manager | 1/11/2023 | 17/6/2026 | The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information. | |
| Modificada | Alta (8.8) | 1.8% | — | Solarwinds Network Configuration Manager | 1/11/2023 | 17/6/2026 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges. | |
| Modificada | Alta (8.8) | 1.8% | — | Solarwinds Network Configuration Manager | 1/11/2023 | 17/6/2026 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. | |
| Modificada | Alta (8.8) | 1.1% | — | Zohocorp Manageengine Network Configuration Manager | 4/8/2023 | 17/6/2026 | An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking. | |
| Modificada | Media (6.5) | 0.49% | — | Solarwinds Network Configuration Manager | 10/10/2022 | 17/6/2026 | An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role. | |
| Modificada | Media (5.3) | 0.58% | — | Teclib-edition System Center Configuration Manager | 22/9/2022 | 17/6/2026 | The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist. |