Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

2145 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.19%—Payplus Payment GatewayAI23/9/202623/9/2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions.
AnalizadaAlta (7.5)0.26%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (6.3)0.08%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection…
AnalizadaAlta (7.4)0.25%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (6.8)0.08%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection…
AnalizadaMedia (6.4)0.11%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and…
AnalizadaBaja (3.7)0.16%—Dell Policy Manager FOR Secure Connect Gateway23/9/202626/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (5.4)0.14%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft.
AnalizadaMedia (6.8)0.21%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
En análisisAlta (7.4)0.50%—Watchguard Authpoint GatewayAI23/9/202624/9/2026
A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Additional authentication factors still apply.
AplazadaMedia (5.3)0.18%—Sumit Payment GatewayAI23/9/202624/9/2026
The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to mark a pending order paid without completing payment.
AplazadaAlta (8.6)0.27%—Jet-form-builder-stripe-gatewayAI23/9/202623/9/2026
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaAlta (7.5)0.46%—UI Unifi GatewayAI22/9/202622/9/2026
A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.
AplazadaMedia (5.3)0.16%—Angelleye Payment Gateway FOR Paypal ON WoocommerceAI21/9/202622/9/2026
The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account before marking an order complete, allowing unauthenticated users to mark their own…
AplazadaMedia (5.3)0.38%—WT Stripe Payment Gateway Stripe FOR WoocommerceAI19/9/202621/9/2026
The Payment Gateway of Stripe for WooCommerce plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in all versions up to, and including, 5.0.8. This is due to the publicly accessible `woocommerce_api_wt_stripe` webhook endpoint (`EH_Stripe_Webhook_Handler::handle()`) wrapping the only…
Pendiente de análisisCrítica (9.1)0.64%—IBM Sterling File GatewayAI18/9/202622/9/2026
IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated session due to improper authentication via an unvalidated SSO header.
AplazadaBaja (3.7)0.14%—Robokassa Payment Gateway FOR WoocommerceAI17/9/202618/9/2026
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold…
Pendiente de análisisAlta (8.2)0.37%—Velocloud EdgeAIVelocloud GatewayAI16/9/202616/9/2026
The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments between authenticated overlay neighbors. This vulnerability impacts the VeloCloud VCMP tunnel protocol only. A successful exploit can cause the affected process to terminate and restart, leading to a…
Pendiente de análisisAlta (7.7)0.67%—Kong API Gateway EnterpriseAI16/9/202618/9/2026
A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing algorithm is compatible with the type of key used for verification. As a result, an…
Pendiente de análisisAlta (7.1)0.36%—Oracle XML GatewayAIOracle E-business SuiteAI15/9/202616/9/2026
Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks of this…
Orbitaley — Vulnerabilidades