Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
11.967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Crítica (9.8) | — | — | Aruba Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | A missing integrity verification vulnerability exists in the OnGuard agent of ClearPass Policy Manager. Successful exploitation could allow an unauthenticated, remote attacker to execute arbitrary code on the affected endpoint with the elevated privileges of the agent. | |
| Recibida | Crítica (9.8) | — | — | HPE Clearpass Policy ManagerAI | 6/10/2026 | 6/10/2026 | Deserialization of untrusted data vulnerabilities exist in the web interface of HPE Networking ClearPass Policy Manager. Successful exploitation could allow an unauthenticated remote attacker to execute arbitrary code on the affected system. | |
| Aplazada | Alta (7.1) | 0.24% | — | Http Requests ManagerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions. | |
| Aplazada | Alta (7.1) | 0.27% | — | Mooberry Book ManagerAI | 6/10/2026 | 6/10/2026 | Subscriber SQL Injection in Mooberry Book Manager 4.16.2 versions. | |
| Aplazada | Alta (7.1) | 0.24% | — | Najeebmedia Frontend File ManagerAI | 6/10/2026 | 6/10/2026 | Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions. | |
| Aplazada | Media (4.3) | 0.15% | — | WDS MCP Content ManagerAI | 6/10/2026 | 6/10/2026 | Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions. | |
| Aplazada | Alta (8.8) | 0.36% | — | Vektor-inc VK Google JOB Posting ManagerAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Stellarwp Advanced Post ManagerAI | 5/10/2026 | 6/10/2026 | Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-post-manager allows Object Injection.This issue affects Advanced Post Manager: from n/a through 4.5.5. | |
| Aplazada | Media (6.5) | 0.20% | — | Wpusermanager WP User ManagerAI | 5/10/2026 | 6/10/2026 | Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20. | |
| Aplazada | Media (5.3) | 0.20% | — | Pixelite Events ManagerAI | 5/10/2026 | 6/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5. | |
| Aplazada | Media (5.3) | 0.23% | — | Magepeople Taxi Booking ManagerAI | 5/10/2026 | 6/10/2026 | Improper Validation of Specified Quantity in Input vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Input Data Manipulation.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.1.1. | |
| Aplazada | Alta (8.8) | 0.37% | — | Smart ManagerAI | 3/10/2026 | 6/10/2026 | The Smart Manager – Advanced WooCommerce Bulk Edit & Inventory Management plugin for WordPress is vulnerable to generic SQL Injection via the 'access_privileges' parameter in all versions up to, and including, 8.97.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | |
| Aplazada | Media (6.4) | 0.22% | — | Download ManagerAI | 2/10/2026 | 3/10/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Pendiente de análisis | Alta (7.5) | 0.33% | — | Fortra Boks ManagerAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service… | |
| Pendiente de análisis | Crítica (9.8) | 0.44% | — | Fortra Core Privileged Access ManagerAI | 1/10/2026 | 1/10/2026 | Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing. | |
| Aplazada | Media (6.3) | 0.25% | — | Wedevs WP Project ManagerAI | 1/10/2026 | 1/10/2026 | Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions. | |
| Pendiente de análisis | Alta (7.9) | 0.07% | — | Fortra Boks ManagerAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the… | |
| Pendiente de análisis | Crítica (9.1) | 0.98% | — | Fortra Boks ManagerAI | 1/10/2026 | 1/10/2026 | Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide… | |
| Aplazada | Media (6.4) | 0.20% | — | Download ManagerAI | 1/10/2026 | 1/10/2026 | The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue,… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Media (6.7) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Media (6.7) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |