Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. | |
| Analizada | Media (6.8) | 0.21% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Pendiente de análisis | Crítica (10) | 1.2% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersonate the service account and access or modify associated cloud resources. | |
| Pendiente de análisis | Alta (8.1) | 0.68% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings. | |
| Pendiente de análisis | Alta (7.6) | 0.46% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.78% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope. | |
| Pendiente de análisis | Alta (8.8) | 0.68% | — | Zohocorp Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zoho Manageengine Applications ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization. | |
| Analizada | Alta (7.1) | 0.18% | — | IBM Financial Transaction Manager | 23/9/2026 | 7/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks. | |
| Pendiente de análisis | Alta (7.4) | 0.39% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector. | |
| Pendiente de análisis | Alta (7.7) | 1.1% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature. | |
| Pendiente de análisis | Alta (8.8) | 3.7% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature. | |
| Pendiente de análisis | Alta (8.8) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability. | |
| Pendiente de análisis | Crítica (9.9) | 2.9% | — | Zoho Manageengine Opmanager MSPAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module. | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. | |
| Pendiente de análisis | Alta (8.1) | 0.85% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import. | |
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. | |
| Pendiente de análisis | Alta (8.8) | 0.97% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. | |
| Pendiente de análisis | Alta (7.6) | 1.5% | — | Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Aplazada | Media (5.6) | 0.17% | — | Wpmanageninja Ninja TablesAI | 23/9/2026 | 23/9/2026 | The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry. | |
| Aplazada | Baja (2.7) | 0.18% | — | Event Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard… | |
| Aplazada | Media (4.3) | 0.15% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking… | |
| Aplazada | Media (6.8) | 0.23% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control. |