Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
11.967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service,… | |
| Pendiente de análisis | Alta (7.8) | 0.10% | — | Nvidia Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering,… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (6.5) | 0.13% | — | Yith Woocommerce TAB ManagerAI | 30/9/2026 | 30/9/2026 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Premmerce Permalink ManagerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. | |
| Aplazada | Media (6.5) | 0.28% | — | MCP Content Manager LiteAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | |
| Aplazada | Alta (8.8) | 0.14% | — | Blacklist ManagerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Admin Notices ManagerAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Pixelmanager Pixel ManagerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. | |
| Analizada | Crítica (9.8) | 1.8% | ⚠ Explotación activa | Cisco Catalyst Sd-wan Manager | 30/9/2026 | 2/10/2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request… | |
| Aplazada | Media (6.4) | 0.19% | — | Real Estate ManagerAI | 30/9/2026 | 30/9/2026 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Baja (3.4) | 0.18% | — | Safe Redirect ManagerAI | 30/9/2026 | 30/9/2026 | The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path. | |
| Aplazada | Alta (7.2) | 0.25% | — | Frontend Post Submission Manager LiteAI | 30/9/2026 | 30/9/2026 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes… | |
| Analizada | Media (5.9) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.4) | 0.15% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.8) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Crítica (9.9) | 0.36% | — | 3DS Geovia Geospatial Data ManagerAI | 29/9/2026 | 30/9/2026 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server. | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 30/9/2026 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their… | |
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 29/9/2026 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session… |