Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
11.986 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Pendiente de análisis | Alta (8.8) | 1.4% | — | Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI | 2/9/2026 | 8/9/2026 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability. | |
| Aplazada | Media (4.3) | 0.17% | — | JetstylemanagerAI | 2/9/2026 | 3/9/2026 | The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into… | |
| Aplazada | Crítica (9.3) | 0.63% | — | Teampasswordmanager Team Password ManagerAI | 1/9/2026 | 23/9/2026 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Rockwellautomation Factorytalk Activation ManagerAI | 1/9/2026 | 1/9/2026 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack… | |
| Aplazada | Media (6.5) | 0.30% | — | Booking AND Rental ManagerAI | 31/8/2026 | 1/9/2026 | Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions. | |
| Aplazada | Media (5.3) | 0.32% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header. | |
| Aplazada | Crítica (9.8) | 0.51% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | |
| Aplazada | Crítica (9.8) | 0.51% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application… | |
| Aplazada | Media (6.5) | 0.35% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint. | |
| Aplazada | Alta (8.1) | 0.53% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.34% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 9/9/2026 | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request. | |
| Aplazada | Media (6.5) | 0.54% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints. | |
| Aplazada | Crítica (9.1) | 0.50% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | |
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists. | |
| Aplazada | Alta (8.8) | 0.52% | — | Booking AND Rental ManagerAI | 27/8/2026 | 28/8/2026 | Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions. | |
| Aplazada | Crítica (9.4) | 0.64% | 💥 PoC | Joomlaeventmanager Joomla Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution. | |
| Aplazada | Media (5.3) | 0.35% | — | Joomla Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. | |
| Aplazada | Media (5.3) | 0.44% | — | Joomlaeventmanager Joomla Events ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector. | |
| Aplazada | Media (5.1) | 0.39% | — | Joomlaeventmanager Joomla Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that… | |
| Aplazada | Media (6.9) | 0.41% | — | Ezcode Event ManagerAI | 27/8/2026 | 28/8/2026 | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event. | |
| Aplazada | Media (4.3) | 0.27% | — | Project ManagerAI | 26/8/2026 | 26/8/2026 | The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read any other user's activity history along with their email address and the details… | |
| Aplazada | Media (5.4) | 0.23% | — | Project ManagerAI | 26/8/2026 | 26/8/2026 | The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards. | |
| Aplazada | Alta (7.5) | 0.40% | — | Project ManagerAI | 26/8/2026 | 26/8/2026 | The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting. |