Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.44% | — | Holest Engineering Selling Commander FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Incorrect Privilege Assignment vulnerability in Holest Engineering Selling Commander for WooCommerce selling-commander-connector allows Privilege Escalation.This issue affects Selling Commander for WooCommerce: from n/a through <= 1.2.46. | |
| Analizada | Alta (7.5) | 0.71% | 💥 PoC | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to a logic error when processing a RADIUS access request for a… | |
| Analizada | Media (4.9) | 0.30% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because certain files lack proper data protection mechanisms. An attacker with read-only Administrator privileges could… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 3.9% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Analizada | Media (5.4) | 0.21% | — | Cisco Identity Services Engine | 5/11/2025 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management… | |
| Aplazada | Crítica (9.8) | 75% | 💥 Exploit | AI EngineAI | 5/11/2025 | 17/6/2026 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the /mcp/v1/ REST API endpoint that exposes the 'Bearer Token' value when 'No-Auth URL' is enabled. This makes it possible for unauthenticated attackers to extract the bearer token, which… | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions before 5723 are vulnerable to Stored Cross Site Scripting in the reports module. | |
| Analizada | Media (5.4) | 0.45% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus versions through 5721 are vulnerable to Stored Cross Site Scripting in the Instant Search option. | |
| Analizada | Media (6.5) | 1.1% | — | Zohocorp Manageengine Exchange Reporter Plus | 30/10/2025 | 17/6/2026 | Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module. | |
| Aplazada | Alta (8.2) | 0.32% | 💥 PoC | SPH Engineering UgcsAI | 29/10/2025 | 17/6/2026 | SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. | |
| Analizada | Media (4.3) | 0.52% | — | Zohocorp Manageengine Endpoint Central | 27/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated user with access to the logs could potentially obtain the sensitive agent token. | |
| Aplazada | Baja (2.7) | 0.22% | — | Shapeshift Shopengine Elementor Woocommerce Builder AddonAI | 25/10/2025 | 17/6/2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check on the post_deactive() function and post_activate() function in all versions up to, and including, 4.8.4. This makes it… | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock JetengineAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Stored XSS.This issue affects JetEngine: from n/a through <= 3.7.3. | |
| Analizada | Media (6.5) | 0.96% | — | Zohocorp Manageengine Applications Manager | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Applications Manager versions 176800 and below are vulnerable to information disclosure in File/Directory monitor. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Admanager Plus | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component. | |
| Analizada | Alta (8.8) | 27% | — | Zohocorp Manageengine Analytics Plus | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine Analytics Plus versions 6171 and prior are vulnerable to authenticated SQL Injection via the key update api. | |
| Analizada | Media (5.3) | 0.34% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. | |
| Analizada | Baja (3.3) | 0.26% | — | Zohocorp Manageengine Endpoint Central | 21/10/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central versions earlier than 11.4.2508.14, 11.4.2516.06, and 11.4.2518.01 are affected by an arbitrary file deletion vulnerability in the agent setup component. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion. | |
| Analizada | Media (5.7) | 0.12% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data. | |
| Analizada | Baja (3.5) | 0.18% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enforcement of server-side security. | |
| Analizada | Baja (3.5) | 0.18% | — | IBM Engineering Requirements Management Doors Next | 12/10/2025 | 17/6/2026 | IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side enforcement of server-side security. | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 17/6/2026 | A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown function of the file /searchjob.php. The manipulation of the argument txtspecialization leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public… | |
| Analizada | Media (5.5) | 0.42% | — | Fabian Online JOB Search Engine | 10/10/2025 | 17/6/2026 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing of the file /registration.php. Performing manipulation of the argument txtusername results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. |