Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.6)0.38%—AdministratorAI26/6/202626/6/2026
Administrator SQL Injection in Popup box <= 6.0.1 versions.
En análisisMedia (4.3)0.18%—Hitachi OPS Center Administrator25/3/202612/8/2026
Open Redirect vulnerability in Hitachi Ops Center Administrator.This issue affects Hitachi Ops Center Administrator: from 10.2.0 before 11.0.8.
Pendiente de análisisAlta (8.7)0.38%—Tibco Activematrix BusinessworksAITibco Enterprise AdministratorAI24/3/202617/6/2026
Injection vulnerabilities due to validation/sanitisation of user-supplied input in ActiveMatrix BusinessWorks and Enterprise Administrator allows information disclosure, including exposure of accessible local files and host system details, and may allow manipulation of application behaviour.
AplazadaMedia (4.3)0.18%—Lobot Slider AdministratorAI21/3/202617/6/2026
The Lobot Slider Administrator plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 0.6.0. This is due to missing or incorrect nonce validation on the fourty_slider_options_page function. This makes it possible for unauthenticated attackers to modify plugin slider-page…
AnalizadaAlta (8.5)0.14%—Siemens TIA Administrator8/7/202517/6/2026
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application allows low-privileged users to trigger installations by overwriting cache files and modifying the downloads path. This would allow an attacker to escalate privilege and exceute arbitrary code.
AnalizadaMedia (6.9)0.07%—Siemens TIA Administrator8/7/202517/6/2026
A vulnerability has been identified in TIA Administrator (All versions < V3.0.6). The affected application improperly validates code signing certificates. This could allow an attacker to bypass the check and exceute arbitrary code during installations.
AplazadaMedia (6.1)0.25%—SAP Businessobjects Content Administrator WorkbenchAI8/7/202517/6/2026
Due to insufficient sanitization in the SAP BusinessObjects Content Administrator Workbench, attackers could craft malicious URLs and execute scripts in a victim�s browser. This could potentially lead to the exposure or modification of web client data, resulting in low impact on confidentiality and integrity, with no…
AplazadaAlta (7)0.36%—Tibco Activematrix AdministratorAI21/5/202517/6/2026
Stored XSS in TIBCO ActiveMatrix Administrator allows malicious data to appear to be part of the website and run within user's browser under the privileges of the web application.
AplazadaMedia (4.9)0.69%—QUY LE 91 Administrator ZAI16/4/202517/6/2026
Path Traversal: '.../...//' vulnerability in Quý Lê 91 Administrator Z administrator-z allows Path Traversal.This issue affects Administrator Z: from n/a through <= 2025.03.28.
AplazadaAlta (8.8)0.37%—QUY LE 91 Administrator ZAI15/4/202517/6/2026
Missing Authorization vulnerability in Quý Lê 91 Administrator Z administrator-z allows Privilege Escalation.This issue affects Administrator Z: from n/a through <= 2025.03.24.
AplazadaMedia (4.3)0.15%—QUY LE 91 Administrator ZAI4/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Quý Lê 91 Administrator Z administrator-z allows Cross Site Request Forgery.This issue affects Administrator Z: from n/a through <= 2026.03.02.
AplazadaMedia (6.5)0.40%—QUY LE 91 Administrator ZAI4/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quý Lê 91 Administrator Z administrator-z allows DOM-Based XSS.This issue affects Administrator Z: from n/a through <= 2026.03.02.
AplazadaAlta (8.8)0.36%—Administrator ZAI28/3/202517/6/2026
The Administrator Z plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the adminz_import_backup() function in all versions up to, and including, 2025.03.24. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.7)0.56%—Siemens Simatic PCS NEOAISiemens Simocode ESAISiemens Sirius Safety ESAISiemens Sirius Soft Starter ESAI+111/2/202517/6/2026
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES…
AplazadaAlta (7.2)0.27%—SAP Netweaver AdministratorAI10/12/202417/6/2026
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and…
AnalizadaAlta (8.1)0.36%—Dell Openmanage Server Administrator9/12/202417/6/2026
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or…
AnalizadaAlta (8.8)0.34%—Dell Openmanage Server Administrator9/12/202417/6/2026
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via the HTTP GET method leading to unauthorized action with elevated privileges.
AplazadaAlta (8.5)0.40%—QUY LE 91 Administrator ZAI9/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quý Lê 91 Administrator Z administrator-z allows Blind SQL Injection.This issue affects Administrator Z: from n/a through < 2024.10.21.
AnalizadaMedia (6.5)0.20%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user without sufficient privileges may be able to use the device identifier to modify an LXCA managed device through a specially crafted web API call.
AnalizadaMedia (4.3)0.34%—Lenovo Xclarity Administrator13/9/202417/6/2026
A valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileges.
AplazadaMedia (6.3)0.28%—Opentext Netiq Directory AND Resource AdministratorAI16/7/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions prior to 10.0.2 and prior to 9.2.1 Patch 10.
AnalizadaMedia (4.8)0.15%—Siemens TIA Administrator11/6/202417/6/2026
A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.
AnalizadaAlta (7.8)0.17%—Dell Openmanage Server Administrator11/6/202417/6/2026
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation…
AplazadaMedia (4.4)0.17%—Hitachi OPS Center AdministratorAI23/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Administrator allows local users to gain sensitive information.This issue affects Hitachi Ops Center Administrator: before 11.0.1.
AplazadaMedia (6.5)0.46%—Lenovo Xclarity AdministratorAI5/4/202417/6/2026
A valid authenticated Lenovo XClarity Administrator (LXCA) user can potentially leverage an unauthenticated API endpoint to retrieve system event information.
Orbitaley — Vulnerabilidades