Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)1.7%—Zohocorp Manageengine Adaudit Plus14/5/202517/6/2026
Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.
AnalizadaAlta (8.1)45%—Zohocorp Manageengine Adselfservice Plus14/5/202517/6/2026
Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.
AnalizadaCrítica (9.8)0.42%—Engineercms Project Engineercms13/5/202517/6/2026
EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.
AnalizadaCrítica (9.8)0.45%—Engineercms Project Engineercms12/5/202517/6/2026
EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
AnalizadaAlta (7.5)0.29%—Broadcom Symantec Eraser Engine30/4/202517/6/2026
Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user.
AplazadaAlta (7.5)0.75%—Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI24/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows PHP Local File Inclusion.This issue…
AplazadaMedia (6.5)0.27%—Crocoblock JetengineAI15/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows DOM-Based XSS.This issue affects JetEngine: from n/a through <= 3.6.4.1.
AplazadaAlta (7.1)0.29%—E1tekoap42 Search Engine Keywords HighlighterAI3/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search engine keywords highlighter keywords-highlight-tool allows Reflected XSS.This issue affects Search engine keywords highlighter: from n/a through <= 0.1.3.
AnalizadaAlta (8.8)1.3%💥 PoCJenkins Templating Engine2/4/202517/6/2026
In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.
ModificadaCrítica (9.8)0.78%—Wptravelengine WP Travel Engine1/4/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5.
ModificadaAlta (7.5)0.98%—Wptravelengine WP Travel Engine27/3/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5.
AplazadaCrítica (9.3)0.40%—Manageengine ServicedeskAI26/3/202517/6/2026
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0.
AnalizadaMedia (5.4)1.1%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcentre Plus21/3/202517/6/2026
Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature.
AnalizadaBaja (3.1)0.28%—Jenkins Zoho Qengine19/3/202517/6/2026
Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it.
AnalizadaMedia (6.9)0.53%—Phpgurukul Local Services Search Engine Management System17/3/202517/6/2026
A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection. The attack may be initiated remotely. The exploit has…
AplazadaAlta (8.2)0.49%—Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI17/3/202521/8/2026
A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials…
AnalizadaAlta (7.5)0.32%—Fortinet Antivirus Engine17/3/202517/6/2026
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the…
AplazadaAlta (7.4)1.3%—Zohocorp Manageengine Analytics PlusAIZohocorp Zoho AnalyticsAI17/3/202517/6/2026
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token.
AnalizadaMedia (6.5)0.19%—IBM Engineering Requirements Management Doors Next3/3/202517/6/2026
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code.
AnalizadaAlta (7.5)0.48%—IBM Engineering Requirements Management Doors Next3/3/202517/6/2026
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.
AnalizadaAlta (7.5)0.48%—IBM Engineering Requirements Management Doors Next3/3/202517/6/2026
IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information.
AnalizadaAlta (8.1)1.5%—Zohocorp Manageengine Adselfservice Plus3/3/202517/6/2026
Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug.
AplazadaAlta (8.8)0.40%—Extremenetworks IQ EngineAI19/2/202517/6/2026
Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service
AplazadaCrítica (9.8)0.76%—Extremenetworks IQ EngineAI19/2/202517/6/2026
Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default.
ModificadaAlta (7.5)0.44%—Enituretechnology Shipengine Shipping Quotes12/2/202517/6/2026
The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated…