Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

61 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.46%—Wpexpertplugins Post Meta Data Manager28/10/202317/6/2026
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_delete_user_meta, pmdm_wp_delete_term_meta, and pmdm_wp_ajax_delete_meta functions in versions up to, and including, 1.2.0. This makes it possible for unauthenticated…
ModificadaAlta (8.8)0.53%—Wpexpertplugins Post Meta Data Manager28/10/202317/6/2026
The Post Meta Data Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pmdm_wp_change_user_meta and pmdm_wp_change_post_meta functions in versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaAlta (8.8)0.77%—Dell Powerprotect Data Manager11/4/202317/6/2026
Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions.
ModificadaMedia (6.5)1.3%—Dell Powerprotect Data ManagerDell Powerprotect X400 Firmware6/7/202017/6/2026
Dell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorization vulnerability. A remote authenticated malicious user may download any file from the affected PowerProtect virtual machines.
ModificadaCrítica (9.8)3.0%—Siemens 7KT Pac1200 Data Manager Firmware27/12/201717/6/2026
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.
ModificadaMedia (5.5)1.1%—Resource Data Management Data Manager Data Manager26/9/201517/6/2026
Resource Data Management Data Manager before 2.2 allows remote authenticated users to modify arbitrary passwords via unspecified vectors.
ModificadaMedia (6.8)0.64%—Resource Data Management Data Manager Data Manager26/9/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in Resource Data Management Data Manager before 2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaMedia (6.5)1.4%—F5 ARX Data Manager18/6/201417/6/2026
SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)24%💥 ExploitOracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager23/12/200216/6/2026
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary code via a long response.
ModificadaAlta (7.5)6.8%—Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager23/12/200216/6/2026
libmysqlclient client library in MySQL 3.x to 3.23.54, and 4.x to 4.0.6, does not properly verify length fields for certain responses in the (1) read_rows or (2) read_one_row routines, which allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.5)20%💥 ExploitOracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager23/12/200216/6/2026
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privileges via a brute force attack using a one-character password, which causes MySQL to only compare the provided password against the first character of the real password.