Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Pendiente de análisisAlta (7.6)1.5%—Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
Pendiente de análisisAlta (8.4)0.11%—Bosch Configuration ManagerAI23/7/20261/10/2026
Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.
AnalizadaAlta (8.8)0.78%💥 PoCMicrosoft Configuration Manager 2503Microsoft Configuration Manager 2509Microsoft Configuration Manager 260314/7/202630/7/2026
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (7.5)0.16%—Hitachi Configuration ManagerHitachi OPS Center API Configuration Manager25/2/202617/6/2026
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.4-00; Hitachi Configuration Manager: from 8.6.1-00 before 11.0.5-00.
AnalizadaMedia (5.2)0.14%💥 PoCHitachi Configuration ManagerHitachi Device ManagerHitachi OPS Center API Configuration Manager25/2/202617/6/2026
Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; Hitachi Configuration Manager: from 8.5.1-00 before…
AnalizadaMedia (6.7)0.35%—Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250311/11/202517/6/2026
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (4.8)3.3%💥 PoCMicrosoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250331/10/202517/6/2026
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.
ModificadaAlta (8.8)0.37%💥 PoCMicrosoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250314/10/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.
ModificadaMedia (6.8)0.68%💥 PoCMicrosoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250314/10/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.
AnalizadaAlta (8)2.7%💥 PoCMicrosoft Configuration Manager 25038/7/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.
AplazadaMedia (4.3)0.25%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+19/6/202517/6/2026
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
AnalizadaCrítica (9.8)81%⚠ Explotación activa💥 PoCMicrosoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 25038/10/202417/6/2026
Microsoft Configuration Manager Remote Code Execution Vulnerability
ModificadaAlta (8.6)47%💥 ExploitZohocorp Manageengine Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+38/1/202417/6/2026
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
ModificadaMedia (5.9)0.56%—Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+1018/12/202317/6/2026
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (8.8)2.1%—Solarwinds Network Configuration Manager9/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227
ModificadaAlta (8.8)3.0%—Solarwinds Network Configuration Manager9/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226
ModificadaMedia (4.9)0.44%—Solarwinds Network Configuration Manager1/11/202317/6/2026
The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to obtain sensitive information.
ModificadaAlta (8.8)1.8%—Solarwinds Network Configuration Manager1/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges.
ModificadaAlta (8.8)1.8%—Solarwinds Network Configuration Manager1/11/202317/6/2026
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges.
ModificadaAlta (8.8)1.1%—Zohocorp Manageengine Network Configuration Manager4/8/202317/6/2026
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The WebSocket endpoint allows Cross-site WebSocket hijacking.
ModificadaMedia (6.5)0.49%—Solarwinds Network Configuration Manager10/10/202217/6/2026
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.
ModificadaMedia (5.3)0.58%—Teclib-edition System Center Configuration Manager22/9/202217/6/2026
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.
Orbitaley — Vulnerabilidades