Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

22.725 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.8)——Aruba Clearpass Policy ManagerAI6/10/20266/10/2026
A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
RecibidaCrítica (9.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
Pendiente de análisisAlta (8.8)——Dell Openmanage IntegrationAI6/10/20266/10/2026
Dell OpenManage Integration with Microsoft Windows Admin Center, versions prior to 3.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote…
AplazadaBaja (2.1)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability was identified in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. This affects an unknown function of the file search_class.php. Such manipulation of the argument school_year leads to sql injection. The attack may be launched remotely. The exploit is publicly…
AplazadaMedia (5.5)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown function of the file student_signup.php of the component Student Registration Endpoint. This manipulation causes sql injection. The attack may be initiated…
AplazadaMedia (5.5)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability was found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The affected element is the function mysql_query of the file admin/login.php of the component Administrator Login Endpoint. The manipulation of the argument username/password results in sql injection.…
Pendiente de análisisBaja (3.5)——HCL Bigfix Service ManagementAI6/10/20266/10/2026
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to supply unexpected or malformed data, enabling processing errors, business logic bypasses, and unintended application behavior.
AplazadaMedia (5.5)——Kusalkasilva Learning Management SystemAI6/10/20266/10/2026
A vulnerability has been found in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. Impacted is the function mysql_error of the file login.php of the component Login Endpoint. The manipulation of the argument username/password leads to sql injection. The attack can be initiated…
AplazadaAlta (7.1)0.24%—Http Requests ManagerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
AplazadaAlta (7.1)0.27%—Mooberry Book ManagerAI6/10/20266/10/2026
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
AplazadaAlta (7.1)0.24%—Najeebmedia Frontend File ManagerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
AplazadaMedia (4.3)0.15%—WDS MCP Content ManagerAI6/10/20266/10/2026
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
AplazadaBaja (2)0.23%—Phpgurukul User Registration Login AND User Management SystemAI6/10/20266/10/2026
A vulnerability was determined in PHPGurukul User Registration & Login and User Management System 3.3. The impacted element is an unknown function of the file loginsystem/admin/change-password.php of the component Change Password Handler. This manipulation of the argument currentpassword causes incorrect…
Pendiente de análisisCrítica (9.3)0.74%—Atlassian Bitbucket Data CenterAIAtlassian Confluence Data CenterAIAtlassian Jira Service Management Data CenterAIAtlassian Jira Software Data CenterAI+45/10/20266/10/2026
This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web…
AplazadaAlta (8.8)0.36%—Vektor-inc VK Google JOB Posting ManagerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
AplazadaCrítica (9.8)0.36%—Stellarwp Advanced Post ManagerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
AplazadaMedia (5.5)0.33%—Onetwothreeneth HospitalmanagementsystemAI5/10/20266/10/2026
A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the function get of the file print.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The…
AplazadaMedia (6.5)0.20%—Wpusermanager WP User ManagerAI5/10/20266/10/2026
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.
AplazadaMedia (5.5)0.26%—Onetwothreeneth Hospitalmanagement SystemAI5/10/20266/10/2026
A vulnerability was determined in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this vulnerability is an unknown functionality of the file transaction_details.php. Executing a manipulation of the argument transaction_id can lead to sql injection. The attack may be…
AplazadaMedia (5.5)0.26%—Onetwothreeneth Hospital Management SystemAI5/10/20266/10/2026
A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been…
AplazadaMedia (5.5)0.29%—Onetwothreeneth Hospital Management SystemAI5/10/20266/10/2026
A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote…
AplazadaMedia (5.3)0.18%—Wpmanageninja Fluent Forms PROAI5/10/20266/10/2026
Missing Authorization vulnerability in WP ManageNinja LLC Fluent Forms Pro Add On Pack fluentformpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Forms Pro Add On Pack: from n/a through 6.2.13.
AplazadaMedia (5.3)0.20%—Pixelite Events ManagerAI5/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5.
AplazadaMedia (5.3)0.23%—Magepeople Taxi Booking ManagerAI5/10/20266/10/2026
Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
AplazadaMedia (5.5)0.26%—Sourcecodester Online Reviewer Management SystemAI5/10/20266/10/2026
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched…