Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.41%—Download ManagerAI18/9/202618/9/2026
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any…
Pendiente de análisisMedia (5.3)0.29%—Caddy Proxy ManagerAI17/9/202623/9/2026
Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without…
Pendiente de análisisAlta (8.5)0.15%—Networkmanager-l2tpAI17/9/202623/9/2026
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers…
AplazadaAlta (8.2)0.28%—Joni1802 TS3 ManagerAI17/9/202630/9/2026
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as…
Pendiente de análisisAlta (8.8)0.69%💥 PoCSolarwinds Access Rights ManagerAI17/9/202618/9/2026
SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key.
AplazadaAlta (7.1)0.25%—Wpinventory WP Inventory ManagerAI17/9/202617/9/2026
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
AplazadaAlta (8.5)0.36%—Product Feed ManagerAI17/9/202617/9/2026
Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions.
En análisisBaja (3.5)0.24%—Dell Smartfabric ManagerAI17/9/202618/9/2026
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
En análisisAlta (8.1)0.20%—Dell Smartfabric ManagerAI17/9/202618/9/2026
Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AplazadaMedia (4.3)0.25%—Checkout Field ManagerAI17/9/202618/9/2026
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
AplazadaMedia (4.3)0.25%—Checkout Field ManagerAI17/9/202618/9/2026
The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users.
AplazadaMedia (4.9)0.38%—Event Booking ManagerAI17/9/202618/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
AplazadaBaja (3.7)0.26%—Event Booking Manager FOR WoocommerceAI17/9/202618/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom…
AplazadaMedia (5.3)0.34%—PatrowlmanagerAI16/9/202623/9/2026
PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the…
AplazadaAlta (7.1)0.38%—PatrowlmanagerAI16/9/202623/9/2026
PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users.
Pendiente de análisisAlta (8.2)0.46%—Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI16/9/202618/9/2026
A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could…
Pendiente de análisisMedia (5.4)0.63%—Adobe Experience ManagerAI16/9/202616/9/2026
Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.…
Pendiente de análisisAlta (8.5)0.32%—Dell Repository ManagerAI16/9/202617/9/2026
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Pendiente de análisisCrítica (9.8)0.48%—Oracle Enterprise Manager FOR Fusion MiddlewareAI15/9/202616/9/2026
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AplazadaAlta (7.2)0.46%—Oracle Identity Manager ConnectorAI15/9/202617/9/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle…
AplazadaAlta (8.8)0.42%—Oracle Identity ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager. Successful…
AplazadaAlta (8.8)0.42%—Oracle E-business SuiteAIOracle Applications ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (7.5)0.32%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided…
AplazadaAlta (8.1)0.37%—Oracle Commerce Guided SearchAIOracle Commerce Experience ManagerAI15/9/202617/9/2026
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge). The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided…