Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

11.967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaCrítica (9.8)——Aruba Clearpass Policy ManagerAI6/10/20266/10/2026
A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent.
RecibidaCrítica (9.8)——HPE Clearpass Policy ManagerAI6/10/20266/10/2026
Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system.
AplazadaAlta (7.1)0.24%—Http Requests ManagerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
AplazadaAlta (7.1)0.27%—Mooberry Book ManagerAI6/10/20266/10/2026
Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions.
AplazadaAlta (7.1)0.24%—Najeebmedia Frontend File ManagerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
AplazadaMedia (4.3)0.15%—WDS MCP Content ManagerAI6/10/20266/10/2026
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
AplazadaAlta (8.8)0.36%—Vektor-inc VK Google JOB Posting ManagerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
AplazadaCrítica (9.8)0.36%—Stellarwp Advanced Post ManagerAI5/10/20266/10/2026
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5.
AplazadaMedia (6.5)0.20%—Wpusermanager WP User ManagerAI5/10/20266/10/2026
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.
AplazadaMedia (5.3)0.20%—Pixelite Events ManagerAI5/10/20266/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5.
AplazadaMedia (5.3)0.23%—Magepeople Taxi Booking ManagerAI5/10/20266/10/2026
Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1.
AplazadaAlta (8.8)0.37%—Smart ManagerAI3/10/20266/10/2026
The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaMedia (5.3)0.33%—Shahjada Download ManagerAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.
AplazadaMedia (6.4)0.22%—Download ManagerAI2/10/20263/10/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
Pendiente de análisisAlta (7.5)0.33%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service…
Pendiente de análisisCrítica (9.8)0.44%—Fortra Core Privileged Access ManagerAI1/10/20261/10/2026
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
AplazadaMedia (6.3)0.25%—Wedevs WP Project ManagerAI1/10/20261/10/2026
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
Pendiente de análisisAlta (7.9)0.07%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the…
Pendiente de análisisCrítica (9.1)0.98%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide…
AplazadaMedia (6.4)0.20%—Download ManagerAI1/10/20261/10/2026
The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue,…
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisMedia (6.7)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisMedia (6.7)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.