Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
11.986 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.13% | — | Najeebmedia Frontend File ManagerAI | 2/8/2026 | 26/8/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,… | |
| Aplazada | Media (5.4) | 0.23% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and… | |
| Aplazada | Media (5.4) | 0.23% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes… | |
| Aplazada | Media (6.6) | 0.59% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce… | |
| Aplazada | Alta (7.5) | 1.0% | — | User Access ManagerAI | 2/8/2026 | 12/8/2026 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.… | |
| Aplazada | Media (6.4) | 0.42% | — | Download ManagerAI | 1/8/2026 | 12/8/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.27% | — | Pixel TAG ManagerAI | 1/8/2026 | 26/8/2026 | The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials. | |
| Aplazada | Media (5.4) | 0.27% | — | Download ManagerAI | 1/8/2026 | 26/8/2026 | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated… | |
| Aplazada | Alta (8.1) | 0.39% | — | Product Feed Manager FOR WoocommerceAI | 31/7/2026 | 26/8/2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | |
| Pendiente de análisis | Alta (7.8) | 0.36% | — | Yggdrasil Worker-package-managerAI | 31/7/2026 | 3/8/2026 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful… | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. | |
| Analizada | Alta (7.4) | 0.13% | — | Devolutions Password Manager | 29/7/2026 | 21/8/2026 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate. | |
| Aplazada | Media (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Analizada | Media (5.9) | 0.26% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |
| Analizada | Alta (8.6) | 0.25% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | |
| Aplazada | Alta (8.8) | 0.73% | — | Eazy Plugin ManagerAI | 28/7/2026 | 28/7/2026 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious scripts that execute in the browser… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store… | |
| Aplazada | Alta (7.1) | 0.61% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting… | |
| Aplazada | Alta (7.1) | 0.25% | — | Product Feed ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | |
| Aplazada | Alta (7.3) | 0.30% | — | Thrive Product ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Booking AND Rental ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+1 | 27/7/2026 | 11/8/2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their… |