Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

591 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.43%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base…
AnalizadaCrítica (9.8)0.51%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Oracle Management Service). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise…
AnalizadaCrítica (9.6)0.47%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AnalizadaCrítica (9.9)0.43%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager…
AnalizadaCrítica (9.9)0.43%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Target Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AnalizadaCrítica (9.6)0.47%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AnalizadaCrítica (9.9)0.43%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager…
ModificadaCrítica (9.9)0.43%—Oracle Enterprise Manager Base Platform17/6/202618/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise…
AplazadaCrítica (9.9)0.55%—Wpusermanager WP User ManagerAI15/6/202617/6/2026
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
Pendiente de análisisMedia (4.7)0.24%—SAP Wily Introscope Enterprise ManagerAI9/6/202623/7/2026
SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certain conditions, when accessed by a victim, the injected script could execute in the user�s browser within the context of the application. This issue has a low impact on the confidentiality and…
AplazadaAlta (7.5)2.7%💥 ExploitWpusermanager WP User ManagerAI6/6/202623/7/2026
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server,…
AnalizadaCrítica (9.1)0.49%—Oracle Enterprise Manager Base Platform21/4/202617/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AplazadaCrítica (9.1)0.52%—Firassaidi Woocommerce License ManagerAI5/3/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.
AplazadaBaja (2.3)0.29%—Silabs PSA CryptoAISilabs SE ManagerAI20/2/202617/6/2026
An integer underflow vulnerability is present in Silicon Lab’s implementation of PSA Crypto and SE Manager EC-JPAKE APIs during ZKP parsing. Triggering the underflow can lead to a hard fault, causing a temporary denial of service.
AnalizadaMedia (4.8)0.23%—Enterprisedb Postgres Enterprise Manager16/1/202617/6/2026
PEM versions prior to 9.8.1 are affected by a stored Cross-site Scripting (XSS) vulnerability that allows users with access to the Manage Charts menu to inject arbitrary JavaScript when creating a new chart, which is then executed by any user accessing the chart. By default only the superuser and users with pem_admin…
AnalizadaAlta (8.8)0.41%—SAP Introscope Enterprise Manager13/1/202617/6/2026
Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthenticated attacker could create a malicious JNLP (Java Network Launch Protocol) file accessible by a public facing URL. When a victim clicks on the URL the accessed Wily Introscope Server could…
AplazadaMedia (6.5)0.19%—Xenioushk BWL Knowledge Base ManagerAI30/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xenioushk BWL Knowledge Base Manager bwl-kb-manager allows Stored XSS.This issue affects BWL Knowledge Base Manager: from n/a through <= 1.6.3.
AplazadaMedia (4.3)0.15%—Purchase AND Expense ManagerAI12/12/202517/6/2026
The Purchase and Expense Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing nonce validation on the 'sup_pt_handle_deletion' function. This makes it possible for unauthenticated attackers to delete arbitrary purchase records via…
AplazadaMedia (6.8)0.82%—Wpusermanager WP User ManagerAI12/12/202517/6/2026
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This…
AplazadaCrítica (9.8)0.52%—Wpusermanager WP User ManagerAI6/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.
AplazadaAlta (7.6)0.37%💥 PoCWpexperts License Manager FOR WoocommerceAI5/9/20255/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.
AnalizadaMedia (5.1)0.21%—Code-projects Daily Expense Manager30/6/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php.
AnalizadaMedia (5.1)0.21%—Code-projects Daily Expense Manager30/6/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php.
AnalizadaAlta (8.7)0.34%—Code-projects Daily Expense Manager30/6/202517/6/2026
user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent using the name parameter in /check.php
AnalizadaAlta (8.7)0.35%—Code-projects Daily Expense Manager30/6/202517/6/2026
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.