Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

22.747 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.14%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.
AnalizadaMedia (6.8)0.21%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Pendiente de análisisCrítica (10)1.2%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources.
Pendiente de análisisAlta (8.1)0.68%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.
Pendiente de análisisAlta (7.6)0.46%—Zohocorp Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope.
Pendiente de análisisAlta (7.1)0.78%—Zoho Manageengine Applications ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.
Pendiente de análisisAlta (8.8)0.68%—Zohocorp Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.
Pendiente de análisisAlta (8.8)2.0%—Zoho Manageengine Applications ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.
AnalizadaMedia (6.5)0.24%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.
AnalizadaAlta (7.1)0.18%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.
Pendiente de análisisAlta (7.4)0.39%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.
Pendiente de análisisAlta (7.7)1.1%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Pendiente de análisisAlta (8.8)3.7%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Pendiente de análisisAlta (8.8)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Pendiente de análisisCrítica (9.9)2.9%—Zoho Manageengine Opmanager MSPAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Pendiente de análisisAlta (7.1)0.60%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Pendiente de análisisAlta (7.1)0.60%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Pendiente de análisisAlta (8.1)0.85%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Pendiente de análisisAlta (7.5)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Pendiente de análisisAlta (8.8)0.97%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
Pendiente de análisisAlta (7.6)1.5%—Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
AplazadaMedia (5.6)0.17%—Wpmanageninja Ninja TablesAI23/9/202623/9/2026
The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry.
AplazadaBaja (2.7)0.18%—Event Booking ManagerAI23/9/202623/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard…
AplazadaMedia (4.3)0.15%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking…
AplazadaMedia (6.8)0.23%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.