Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
2650 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 1.7% | — | Zohocorp Manageengine Adaudit Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report. | |
| Analizada | Alta (8.1) | 45% | — | Zohocorp Manageengine Adselfservice Plus | 14/5/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. | |
| Analizada | Crítica (9.8) | 0.42% | — | Engineercms Project Engineercms | 13/5/2025 | 17/6/2026 | EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface. | |
| Analizada | Crítica (9.8) | 0.45% | — | Engineercms Project Engineercms | 12/5/2025 | 17/6/2026 | EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface. | |
| Analizada | Alta (7.5) | 0.29% | — | Broadcom Symantec Eraser Engine | 30/4/2025 | 17/6/2026 | Symantec Endpoint Protection Windows Agent, running an ERASER Engine prior to 119.1.7.8, may be susceptible to an Elevation of Privilege vulnerability, which may allow an attacker to delete resources that are normally protected from an application or user. | |
| Aplazada | Alta (7.5) | 0.75% | — | Holest Engineering Spreadsheet Price Changer FOR Woocommerce AND WP E-commerce LightAI | 24/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light excel-like-price-change-for-woocommerce-and-wp-e-commerce-light allows PHP Local File Inclusion.This issue… | |
| Aplazada | Media (6.5) | 0.27% | — | Crocoblock JetengineAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows DOM-Based XSS.This issue affects JetEngine: from n/a through <= 3.6.4.1. | |
| Aplazada | Alta (7.1) | 0.29% | — | E1tekoap42 Search Engine Keywords HighlighterAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e1tekoap42 Search engine keywords highlighter keywords-highlight-tool allows Reflected XSS.This issue affects Search engine keywords highlighter: from n/a through <= 0.1.3. | |
| Analizada | Alta (8.8) | 1.3% | 💥 PoC | Jenkins Templating Engine | 2/4/2025 | 17/6/2026 | In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM. | |
| Modificada | Crítica (9.8) | 0.78% | — | Wptravelengine WP Travel Engine | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5. | |
| Modificada | Alta (7.5) | 0.98% | — | Wptravelengine WP Travel Engine | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Travel Engine WP Travel Engine wp-travel-engine allows PHP Local File Inclusion.This issue affects WP Travel Engine: from n/a through <= 6.3.5. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Manageengine ServicedeskAI | 26/3/2025 | 17/6/2026 | Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged account to gain additional administrative permissions in the application.This issue affects OXARI ServiceDesk in versions before 2.0.324.0. | |
| Analizada | Media (5.4) | 1.1% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcentre Plus | 21/3/2025 | 17/6/2026 | Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature. | |
| Analizada | Baja (3.1) | 0.28% | — | Jenkins Zoho Qengine | 19/3/2025 | 17/6/2026 | Jenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attackers to observe and capture it. | |
| Analizada | Media (6.9) | 0.53% | — | Phpgurukul Local Services Search Engine Management System | 17/3/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Aplazada | Alta (8.2) | 0.49% | — | Redhat Multicluster EngineAIRedhat Advanced Cluster ManagementAIRedhat HiveAI | 17/3/2025 | 21/8/2026 | A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials… | |
| Analizada | Alta (7.5) | 0.32% | — | Fortinet Antivirus Engine | 17/3/2025 | 17/6/2026 | FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the… | |
| Aplazada | Alta (7.4) | 1.3% | — | Zohocorp Manageengine Analytics PlusAIZohocorp Zoho AnalyticsAI | 17/3/2025 | 17/6/2026 | Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are vulnerable to an AD only account takeover because of a hardcoded sensitive token. | |
| Analizada | Media (6.5) | 0.19% | — | IBM Engineering Requirements Management Doors Next | 3/3/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a user to download a malicious file without verifying the integrity of the code. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Engineering Requirements Management Doors Next | 3/3/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information. | |
| Analizada | Alta (7.5) | 0.48% | — | IBM Engineering Requirements Management Doors Next | 3/3/2025 | 17/6/2026 | IBM Engineering Requirements Management DOORS Next 7.0.2, 7.0.3, and 7.1 could allow a remote attacker to download temporary files which could expose application logic or other sensitive information. | |
| Analizada | Alta (8.1) | 1.5% | — | Zohocorp Manageengine Adselfservice Plus | 3/3/2025 | 17/6/2026 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. | |
| Aplazada | Alta (8.8) | 0.40% | — | Extremenetworks IQ EngineAI | 19/2/2025 | 17/6/2026 | Buffer Overflow vulnerability in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, allows an attacker to execute arbitrary code via the implementation of the ah_auth service | |
| Aplazada | Crítica (9.8) | 0.76% | — | Extremenetworks IQ EngineAI | 19/2/2025 | 17/6/2026 | Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has a buffer overflow. This issue arises from the ah_webui service, which listens on TCP port 3009 by default. | |
| Modificada | Alta (7.5) | 0.44% | — | Enituretechnology Shipengine Shipping Quotes | 12/2/2025 | 17/6/2026 | The ShipEngine Shipping Quotes plugin for WordPress is vulnerable to SQL Injection via the 'edit_id' parameter in all versions up to, and including, 1.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated… |