Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.4)0.22%—Events ManagerAI5/9/20268/9/2026
The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values (using only `wp_unslash()` without…
Pendiente de análisisCrítica (9.1)0.68%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
Pendiente de análisisCrítica (9.1)0.46%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
Pendiente de análisisCrítica (9.1)1.6%—Sonicwall Network Security ManagerAI4/9/20268/9/2026
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that are executed on the underlying host,…
Pendiente de análisisCrítica (9.8)0.43%—IBM Operational Decision ManagerAI4/9/202610/9/2026
IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web root, resulting in remote code execution.
AplazadaMedia (5.3)0.32%—E-cab E CAB Taxi Booking ManagerAI4/9/20268/9/2026
The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pricing a booking, allowing unauthenticated attackers to manipulate the order total down to zero and place real taxi-booking orders at an arbitrary…
AplazadaMedia (6.9)0.41%—Lightstar Smartit Desktop ManagerAILightstar Smartit AgentAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
AplazadaCrítica (9.3)0.63%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
AplazadaAlta (8.7)0.33%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
AplazadaCrítica (9.3)0.63%—Lightstar Smartit Desktop ManagerAI4/9/20268/9/2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
AplazadaMedia (6.5)0.22%—Magepeople Booking AND Rental ManagerAI3/9/20263/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This issue affects Booking and Rental Manager: from n/a through 2.7.7.
AplazadaAlta (7.1)0.25%—Fullworksplugins Quick Event ManagerAI3/9/20264/9/2026
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
AplazadaAlta (7.5)0.35%—Fullworksplugins Quick Event ManagerAI3/9/20265/9/2026
Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
AnalizadaAlta (8.4)0.22%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+43/9/20269/9/2026
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon…
AplazadaAlta (8.3)0.41%—Helicone VaultmanagerAI3/9/202624/9/2026
Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider…
En análisisMedia (6.5)0.41%—Dell Powerprotect Data ManagerAI3/9/20265/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass.
En análisisMedia (4.1)0.36%—Dell Powerprotect Data ManagerAI3/9/20263/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
En análisisAlta (7.8)0.20%—Dell Powerprotect Data ManagerAI3/9/20264/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure.
En análisisMedia (6.8)0.38%—Dell Powerprotect Data ManagerAI3/9/20264/9/2026
Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks.
AnalizadaAlta (7.5)0.36%—Wso2 API Control PlaneWso2 API Manager3/9/202615/9/2026
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to…
AnalizadaAlta (7.1)0.29%—Sonatype Nexus Repository Manager2/9/202622/9/2026
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group…
AnalizadaAlta (7.5)0.72%—Sonatype Nexus Repository Manager2/9/202622/9/2026
In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether script execution had been administratively disabled. An account holding script-execution permission could continue to run previously-created scripts even after an administrator set…
AnalizadaMedia (6)0.46%—Sonatype Nexus Repository Manager2/9/202622/9/2026
Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus…
AnalizadaMedia (5.3)0.28%—Sonatype Nexus Repository Manager2/9/202622/9/2026
An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve metadata for member repositories on which it held no direct permission, by…
AnalizadaMedia (5.3)0.25%—Sonatype Nexus Repository Manager2/9/20267/10/2026
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository…