Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (4.8) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files. | |
| Aplazada | Alta (7.5) | 0.46% | — | Ayecode Location ManagerAI | 18/9/2026 | 18/9/2026 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| En análisis | Alta (7.6) | 0.28% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover, and unauthorized actions on behalf of affected users. | |
| En análisis | Alta (8.1) | 0.35% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged roles. | |
| En análisis | Crítica (9.3) | 0.34% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 21/9/2026 | HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not accessible from the internet. | |
| En análisis | Crítica (9.8) | 0.47% | — | HCL Bigfix Service ManagementAI | 18/9/2026 | 18/9/2026 | HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well as manipulate request values to gain unauthorized access to full personal profile… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpinventory WP Inventory ManagerAI | 18/9/2026 | 18/9/2026 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in… | |
| Aplazada | Media (6.5) | 0.41% | — | Download ManagerAI | 18/9/2026 | 18/9/2026 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any… | |
| Pendiente de análisis | Alta (7.7) | 1.5% | — | Manageengine Datasecurity PlusAI | 18/9/2026 | 18/9/2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module. | |
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Manageengine Datasecurity PlusAI | 18/9/2026 | 18/9/2026 | ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication. | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | Frappe Learning Management SystemAI | 17/9/2026 | 23/9/2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The renderer constructs and opens a server-side path without first confirming that its… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Caddy Proxy ManagerAI | 17/9/2026 | 23/9/2026 | Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Networkmanager-l2tpAI | 17/9/2026 | 23/9/2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers… | |
| Aplazada | Alta (8.2) | 0.28% | — | Joni1802 TS3 ManagerAI | 17/9/2026 | 30/9/2026 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as… | |
| Pendiente de análisis | Alta (8.8) | 0.69% | 💥 PoC | Solarwinds Access Rights ManagerAI | 17/9/2026 | 18/9/2026 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpinventory WP Inventory ManagerAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | |
| Pendiente de análisis | Media (5.9) | 0.44% | — | Steeltoe.management.endpointAI | 17/9/2026 | 23/9/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query… | |
| Aplazada | Alta (8.5) | 0.36% | — | Product Feed ManagerAI | 17/9/2026 | 17/9/2026 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | |
| Analizada | Media (6.8) | 0.13% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. | |
| Analizada | Alta (7.4) | 0.37% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.2) | 0.46% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.3) | 0.14% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| En análisis | Baja (3.5) | 0.24% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Alta (8.1) | 0.20% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (6.5) | 0.45% | — | Dell Openmanage Server Administrator | 17/9/2026 | 6/10/2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |