Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
11.986 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.36% | 💥 PoC | Ekushey Project Manager CRMAI | 25/8/2026 | 24/9/2026 | Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element, the title element, and the text of an h4 element in the page header. The h4… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (5.8) | 0.61% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (6.5) | 0.38% | — | WP Project Manager PROAI | 25/8/2026 | 28/9/2026 | The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Media (6.1) | 0.41% | 💥 PoC | Events ManagerAI | 25/8/2026 | 26/8/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'header_format' parameter in all versions up to, and including, 7.4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.6) | 0.97% | — | Events ManagerAI | 25/8/2026 | 26/8/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.3.7.4 via the em_options_save function. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute… | |
| Aplazada | Media (5.3) | 0.47% | — | Events Calendar Manager Events ManagerAI | 25/8/2026 | 27/8/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.52% | — | Codeat3 Events ManagerAI | 25/8/2026 | 26/8/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection via Stored 'meta_key' via Event/Location Duplicate Action in all versions up to, and including, 7.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Wedevs WP Project ManagerAI | 24/8/2026 | 27/8/2026 | Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions. | |
| Pendiente de análisis | Media (4.3) | 0.15% | — | Devolutions Remote Desktop ManagerAIIronvncAI | 24/8/2026 | 28/8/2026 | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication. | |
| Pendiente de análisis | Alta (7.1) | 0.14% | — | NetworkmanagerAI | 24/8/2026 | 28/8/2026 | NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory,… | |
| Aplazada | Media (5.3) | 0.31% | — | Booking AND Rental ManagerAI | 24/8/2026 | 24/8/2026 | Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | WP Project Manager PROAI | 24/8/2026 | 24/8/2026 | Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions. | |
| Pendiente de análisis | Media (6.9) | 0.08% | — | Johnsoncontrols Simplex Incident ManagerAIJohnsoncontrols Autocall Fire AdministratorAI | 21/8/2026 | 3/9/2026 | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05. | |
| Analizada | Alta (8.8) | 0.74% | — | Microsoft Azure Data Manager FOR Energy | 20/8/2026 | 4/9/2026 | Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Alta (7.1) | 0.51% | — | Amazon AthenaAIAmazon Athena Federated QueryAIAmazon Secrets ManagerAI | 20/8/2026 | 25/8/2026 | Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at… | |
| Pendiente de análisis | Media (4.3) | 0.21% | — | RSA Securid Authentication ManagerAISplunk SoarAI | 19/8/2026 | 20/8/2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Otto Fleet ManagerAI | 19/8/2026 | 28/8/2026 | A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. If an attacker… | |
| Pendiente de análisis | Media (6.2) | 0.54% | — | Volsync Addon-controllerAIRedhat Openshift Lifecycle ManagerAI | 19/8/2026 | 8/9/2026 | A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful… | |
| Aplazada | Media (6.5) | 0.30% | — | Taxi Booking ManagerAI | 19/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | |
| Aplazada | Alta (8.5) | 0.32% | — | Advancedfilemanager Advanced File ManagerAI | 19/8/2026 | 26/8/2026 | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive… | |
| Analizada | Media (4.3) | 0.33% | — | Oracle Access Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager.… |