Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
Pendiente de análisisAlta (8.8)1.4%—Zoho Password Manager PROAIZoho Pam360AIZoho Access Manager PlusAI2/9/20268/9/2026
Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticated SQL Injection vulnerability.
AplazadaMedia (4.3)0.17%—JetstylemanagerAI2/9/20263/9/2026
The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with the edit_posts capability (Contributor and above) delete or modify custom widget skins via a crafted request, provided they can trick the user into…
AplazadaCrítica (9.3)0.63%—Teampasswordmanager Team Password ManagerAI1/9/202623/9/2026
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
Pendiente de análisisAlta (8.5)0.11%—Rockwellautomation Factorytalk Activation ManagerAI1/9/20261/9/2026
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack…
AplazadaMedia (6.5)0.30%—Booking AND Rental ManagerAI31/8/20261/9/2026
Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.
AplazadaMedia (5.3)0.32%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20261/9/2026
Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header.
AplazadaCrítica (9.8)0.51%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
AplazadaCrítica (9.8)0.51%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application…
AplazadaMedia (6.5)0.35%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.
AplazadaMedia (5.3)0.36%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.
AplazadaAlta (8.1)0.53%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
AplazadaMedia (5.3)0.34%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20269/9/2026
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request.
AplazadaMedia (6.5)0.54%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
AplazadaCrítica (9.1)0.50%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20262/9/2026
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
AplazadaMedia (5.3)0.36%💥 PoCVeno File Manager Project Veno File ManagerAI27/8/20261/9/2026
User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists.
AplazadaAlta (8.8)0.52%—Booking AND Rental ManagerAI27/8/202628/8/2026
Contributor PHP Object Injection in Booking and Rental Manager <= 2.7.5 versions.
AplazadaCrítica (9.4)0.64%💥 PoCJoomlaeventmanager Joomla Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.
AplazadaMedia (5.3)0.35%—Joomla Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
AplazadaMedia (5.3)0.44%—Joomlaeventmanager Joomla Events ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
AplazadaMedia (5.1)0.39%—Joomlaeventmanager Joomla Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that…
AplazadaMedia (6.9)0.41%—Ezcode Event ManagerAI27/8/202628/8/2026
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
AplazadaMedia (4.3)0.27%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not check that the user whose activity is being requested is the one making the request in one of its REST API routes, allowing any authenticated user, such as a subscriber, to read any other user's activity history along with their email address and the details…
AplazadaMedia (5.4)0.23%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a user belongs to, allowing any authenticated user, such as a subscriber, to read other projects' task content and user email addresses and to modify other projects' task boards.
AplazadaAlta (7.5)0.40%—Project ManagerAI26/8/202626/8/2026
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.