Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
22.748 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 14/9/2026 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.57% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 16/9/2026 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Baja (2.1) | 0.37% | — | Jaychouchannel Tourism-management-systemAI | 13/9/2026 | 19/9/2026 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Alta (8.5) | 0.15% | — | Tonec Internet Download ManagerAI | 13/9/2026 | 15/9/2026 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for… | |
| Aplazada | Media (4.9) | 0.33% | — | Product XML Feed ManagerAI | 12/9/2026 | 14/9/2026 | The Product XML Feed Manager for WooCommerce WordPress plugin before 3.1.1 does not restrict which object method its product shortcode may call, nor check the user's capability over the targeted product, allowing users with contributor-level access to delete arbitrary WooCommerce products by previewing a post that… | |
| Aplazada | Alta (8.4) | 0.10% | — | Lenovo File ManagerAI | 10/9/2026 | 11/9/2026 | A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application. | |
| Pendiente de análisis | Alta (8.5) | 0.66% | — | Amazon Systems Manager AgentAI | 10/9/2026 | 10/9/2026 | A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist… | |
| Pendiente de análisis | Crítica (9.9) | 0.65% | — | Plesk Backup ManagerAI | 10/9/2026 | 10/9/2026 | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer. | |
| Aplazada | Alta (7.5) | 0.50% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Crítica (9.8) | 0.47% | — | GIS Informatics Gislab Laboratory Management SystemAI | 10/9/2026 | 10/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5. | |
| Aplazada | Alta (7.2) | 0.40% | — | Sidebar Manager LightAI | 10/9/2026 | 28/9/2026 | El plugin Sidebar Manager Light para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'sbm_description' en todas las versiones hasta la 1.18, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite que atacantes no autenticados inyecten scripts… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 14/9/2026 | A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 10/9/2026 | 10/9/2026 | A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.76% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 10/9/2026 | A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Such manipulation of the argument order_date/invoice_no leads to missing… | |
| Aplazada | Baja (2.1) | 0.47% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 11/9/2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handler. This manipulation of the argument category_name/brand_name/product_name causes… | |
| Aplazada | Media (5.5) | 0.69% | — | Rizwan17 Inventory Management SystemAI | 9/9/2026 | 10/9/2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function DBOperation.addCategory of the file includes/process.php of the component AJAX Backend. The manipulation of the argument userid results in missing… | |
| Aplazada | Media (5.5) | 0.43% | — | Rizwan17 Inventory-management-systemAI | 9/9/2026 | 14/9/2026 | A vulnerability was identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is the function update_record of the file includes/manage.php. The manipulation of the argument update_category/cid/update_brand/update_product leads to sql injection. The attack is possible… | |
| Pendiente de análisis | Crítica (9.8) | 3.7% | — | Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI | 9/9/2026 | 10/9/2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpmr Google Feed Manager FOR WoocommerceAI | 9/9/2026 | 9/9/2026 | The WPMR Google Feed Manager for WooCommerce – Sell on Google Merchant Center & Shopping plugin for WordPress is vulnerable to time-based SQL Injection via the 'feed' parameter in all versions up to, and including, 2.23.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Aplazada | Media (6.1) | 0.21% | — | User Access ManagerAI | 9/9/2026 | 11/9/2026 | The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 8/9/2026 | 10/9/2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 8/9/2026 | 10/9/2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 8/9/2026 | 10/9/2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.… | |
| Analizada | Media (5.4) | 0.39% | — | Adobe Experience Manager | 8/9/2026 | 11/9/2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.… |