Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.32%—User Access ManagerAI12/8/202626/8/2026
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Pendiente de análisisAlta (7)0.16%—AMD Power Design ManagerAI11/8/202629/9/2026
Una vulnerabilidad de secuestro de DLL en AMD Power Design Manager podría permitir a un atacante local malicioso escalar privilegios durante el proceso de desinstalación, lo que podría resultar en ejecución de código arbitrario.
Pendiente de análisisAlta (8.1)1.5%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
Pendiente de análisisAlta (7.7)0.72%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
Pendiente de análisisAlta (7.5)1.6%—Ivanti Endpoint ManagerAI11/8/202631/8/2026
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Pendiente de análisisAlta (8.5)1.8%—Zohocorp Manageengine M365 Manager PlusAIZohocorp Manageengine M365 Security PlusAI11/8/202631/8/2026
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
AplazadaAlta (7.5)0.42%—File ManagerAI10/8/202626/8/2026
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents…
AplazadaAlta (7.5)0.43%—File ManagerAI10/8/202626/8/2026
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
AplazadaAlta (8.8)0.42%—File ManagerAI10/8/202626/8/2026
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to…
AnalizadaAlta (8.7)0.48%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection.…
AnalizadaAlta (8.9)0.29%—Sonatype Nexus Repository Manager7/8/202623/9/2026
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.
AnalizadaAlta (8.7)0.25%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing…
AnalizadaMedia (6.9)0.34%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding…
AnalizadaMedia (5.3)0.23%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the…
AnalizadaMedia (5.1)0.23%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the server to attempt outbound network…
AnalizadaMedia (6.3)0.24%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status.…
AnalizadaMedia (5.3)0.23%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and…
AnalizadaAlta (8.2)0.74%💥 ExploitSonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different,…
AnalizadaAlta (7.2)0.77%—Sonatype Nexus Repository Manager7/8/202622/9/2026
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because…
AnalizadaAlta (8.6)0.34%—Sonatype Nexus Repository Manager7/8/202622/9/2026
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.
AplazadaMedia (5.3)0.16%—Wpeventsmanager WP Events ManagerAI7/8/202626/8/2026
The WP Events Manager WordPress plugin before 2.2.5 does not verify that an incoming payment notification originates from the site's configured merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to mark any booking as paid without a legitimate payment reaching the…
AplazadaCrítica (9.8)0.48%—Wpeventsmanager WP Events ManagerAI7/8/202626/8/2026
The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without making a payment.
AplazadaMedia (5.3)0.32%—Event Booking Manager FOR WoocommerceAI6/8/202626/8/2026
The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to…
AplazadaAlta (7.1)0.25%—Wpide File Manager AND Code EditorAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
AplazadaAlta (7.1)0.13%—Data443 Tracking Code ManagerAI6/8/202612/8/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.