Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Events ManagerAI6/8/202622/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2.
AnalizadaCrítica (9.8)0.48%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/8/202610/8/2026
Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This…
AnalizadaMedia (4.4)0.16%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/8/202612/8/2026
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such…
AnalizadaMedia (4.9)0.19%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/8/202613/8/2026
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client…
AnalizadaAlta (7.5)0.41%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/8/20269/8/2026
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the…
En análisisMedia (5.8)0.29%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+36/8/20269/8/2026
The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious…
AplazadaAlta (7.5)0.43%—Events ManagerAI6/8/202626/8/2026
The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to…
AnalizadaCrítica (10)0.59%⚠ Explotación activa💥 PoCWso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/8/202625/9/2026
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result…
AnalizadaCrítica (9.4)0.67%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+56/8/202629/9/2026
El script de autenticación condicional (autenticación adaptativa) no aplica correctamente la finalización de todos los pasos de autenticación requeridos cuando se configura un patrón específico de múltiples pasos que involucra ciertos autenticadores. Esto permite a un atacante eludir los desafíos de autenticación…
AnalizadaBaja (3.7)0.27%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+16/8/202629/9/2026
Cuando el inicio de sesión multiatributo está habilitado, la interfaz de inicio de sesión no logra enmascarar consistentemente la existencia de cuentas de usuario. Para usuarios válidos, el servidor resuelve y muestra su nombre de usuario canónico, mientras que para usuarios inexistentes, se hace eco de la entrada…
AnalizadaMedia (5.4)0.14%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+56/8/202629/9/2026
El procesador Ajax dentro de la consola Carbon no protege adecuadamente las operaciones que cambian el estado de ataques de falsificación de petición en sitios cruzados (CSRF). Específicamente, utiliza el método HTTP GET para estas operaciones, y aunque el atributo de cookie SameSite=Lax se emplea para la mitigación,…
AplazadaAlta (8.8)1.1%—File ManagerAI6/8/202612/8/2026
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server,…
Pendiente de análisisMedia (4.3)0.29%—Jenkins External Workspace Manager PluginAI5/8/202631/8/2026
Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in…
Pendiente de análisisMedia (4.2)0.19%—Jenkins Scm-manager PluginAI5/8/202631/8/2026
A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Pendiente de análisisMedia (4.2)0.11%—Jenkins Scm-manager PluginAI5/8/202631/8/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
Pendiente de análisisMedia (6.5)0.13%—Cisco Catalyst Sd-wan ManagerAI5/8/20266/8/2026
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included…
AnalizadaAlta (8.8)0.49%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
AnalizadaCrítica (9.8)0.65%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use…
AplazadaAlta (7.2)0.50%—Wpdownloadmanager WP DownloadmanagerAI5/8/202626/8/2026
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no…
AplazadaMedia (6.5)0.45%—User Access ManagerAI5/8/202612/8/2026
The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and…
AplazadaMedia (5.5)0.50%—ResponsivefilemanagerAI4/8/202612/8/2026
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaAlta (7.3)0.19%—Geovision Gv-asmanagerAI4/8/20269/9/2026
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed…
AnalizadaAlta (7.8)0.17%—Dell Display AND Peripheral Manager3/8/20265/8/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.8)0.15%—Dell Display AND Peripheral Manager3/8/20265/8/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
AplazadaBaja (2.7)0.30%—TAG Category Taxonomy ManagerAI3/8/202626/8/2026
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.