Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

2649 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.6)1.7%—Zohocorp Manageengine Adselfservice PlusAI22/9/202622/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.
Pendiente de análisisCrítica (9.8)4.6%—Zohocorp Manageengine Adselfservice PlusAI22/9/202623/9/2026
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
AplazadaAlta (7.5)0.58%—Wptravelengine WP Travel EngineAI22/9/202622/9/2026
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and…
AplazadaBaja (2.1)0.45%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the…
AplazadaBaja (2.1)0.46%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has…
AplazadaAlta (7.1)0.63%—Arcadedb-engineAI18/9/202622/9/2026
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare class name, which is matched by exact equality and therefore does not cover its…
AplazadaMedia (5.3)0.29%—Arcadedb-engineAI18/9/202618/9/2026
ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Because those workers have no current user, LocalDatabase.checkPermissionsOnFile…
AplazadaAlta (7.1)0.44%—Arcadedb-engineAI18/9/202618/9/2026
ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or the TimeSeries engine never invoke that permission check, so an authenticated user…
Pendiente de análisisAlta (7.7)1.5%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.
Pendiente de análisisAlta (7.5)1.1%—Manageengine Datasecurity PlusAI18/9/202618/9/2026
ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.
Pendiente de análisisAlta (8.8)0.32%—Wpengine FaustwpAI17/9/202624/9/2026
Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() and WPE\FaustWP\Auth\decrypt() in plugins/faustwp/includes/auth/functions.php. A…
AplazadaCrítica (9.8)0.63%—PressengineAI17/9/202618/9/2026
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.
AnalizadaCrítica (10)14%⚠ Explotación activaCisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202625/9/2026
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (4.9)0.43%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs…
AnalizadaMedia (5.3)0.38%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine16/9/202628/9/2026
A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP…
AnalizadaMedia (4.9)0.30%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific&nbsp;files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability…
AnalizadaMedia (5.3)0.29%—Cisco Identity Services Engine Passive Identity ConnectorCisco Identity Services Engine16/9/202628/9/2026
A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could…
AnalizadaMedia (5.3)0.32%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to insufficient authentication on an internal…
AnalizadaMedia (4.9)0.38%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This…
AnalizadaMedia (5.3)1.3%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the…
AnalizadaMedia (4.9)1.2%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does not properly validate directory traversal…
AnalizadaMedia (4.9)1.2%—Cisco Identity Services EngineCisco Identity Services Engine Passive Identity Connector16/9/202628/9/2026
A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.…