Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
11.986 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially… | |
| Aplazada | Baja (1.8) | 0.20% | 💥 PoC | ZTE File ManagerAI | 27/7/2026 | 28/7/2026 | The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level… | |
| Aplazada | Alta (7.5) | 0.39% | — | Download ManagerAI | 27/7/2026 | 27/7/2026 | The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected… | |
| Aplazada | Media (4.8) | 0.24% | — | Smart ManagerAI | 27/7/2026 | 27/7/2026 | The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. | |
| Aplazada | Media (5.9) | 0.24% | — | Shop Manager TabsAI | 23/7/2026 | 23/7/2026 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Legoeso PDF ManagerAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Smart ManagerAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Real Estate Manager PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | |
| Aplazada | Alta (7.1) | 0.16% | — | Linux-gaming PortprotonqtAIGnome NetworkmanagerAI | 23/7/2026 | 23/7/2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe. | |
| Pendiente de análisis | Alta (8.4) | 0.11% | — | Bosch Configuration ManagerAI | 23/7/2026 | 1/10/2026 | Revelación de información en Bosch Configuration Manager en la Versión 7.72.0106 permite a un atacante acceder a información sensible. | |
| Aplazada | Alta (8.8) | 0.20% | — | JoomlaAIRegularlabs Extension ManagerAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could… | |
| Aplazada | Alta (7.5) | 0.39% | — | Regularlabs Conditions ManagerAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules. | |
| Aplazada | Media (4.8) | 0.24% | — | Regularlabs Conditions ManagerAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries. | |
| Aplazada | Alta (8.8) | 0.20% | — | Regularlabs Conditions ManagerAI | 22/7/2026 | 27/7/2026 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.63% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (4.4) | 0.15% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Alta (7.5) | 0.45% | — | Events ManagerAI | 22/7/2026 | 22/7/2026 | The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget… |