Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.19% | — | Payplus Payment GatewayAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. | |
| Analizada | Alta (7.5) | 0.26% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Media (6.3) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection… | |
| Analizada | Alta (7.4) | 0.25% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (6.8) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection… | |
| Analizada | Media (6.4) | 0.11% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and… | |
| Analizada | Baja (3.7) | 0.16% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 26/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Media (5.4) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. | |
| Analizada | Media (6.8) | 0.21% | — | Dell Policy Manager FOR Secure Connect Gateway | 23/9/2026 | 25/9/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| En análisis | Alta (7.4) | 0.50% | — | Watchguard Authpoint GatewayAI | 23/9/2026 | 24/9/2026 | A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply. | |
| Aplazada | Media (5.3) | 0.18% | — | Sumit Payment GatewayAI | 23/9/2026 | 24/9/2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment. | |
| Aplazada | Alta (8.6) | 0.27% | — | Jet-form-builder-stripe-gatewayAI | 23/9/2026 | 23/9/2026 | The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Alta (7.5) | 0.46% | — | UI Unifi GatewayAI | 22/9/2026 | 22/9/2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device. | |
| Aplazada | Media (5.3) | 0.16% | — | Angelleye Payment Gateway FOR Paypal ON WoocommerceAI | 21/9/2026 | 22/9/2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own… | |
| Aplazada | Media (5.3) | 0.38% | — | WT Stripe Payment Gateway Stripe FOR WoocommerceAI | 19/9/2026 | 21/9/2026 | The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only… | |
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | IBM Sterling File GatewayAI | 18/9/2026 | 22/9/2026 | IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header. | |
| Aplazada | Baja (3.7) | 0.14% | — | Robokassa Payment Gateway FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold… | |
| Pendiente de análisis | Alta (8.2) | 0.37% | — | Velocloud EdgeAIVelocloud GatewayAI | 16/9/2026 | 16/9/2026 | The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful exploit can cause the affected process to terminate and restart, leading to a… | |
| Pendiente de análisis | Alta (7.7) | 0.67% | — | Kong API Gateway EnterpriseAI | 16/9/2026 | 18/9/2026 | A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an… | |
| Pendiente de análisis | Alta (7.1) | 0.36% | — | Oracle XML GatewayAIOracle E-business SuiteAI | 15/9/2026 | 16/9/2026 | Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this… |