Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)7.9%—Zohocorp Manageengine Admanager Plus17/8/202317/6/2026
ADManager Plus versión 7182 y anteriores de ManageEngine de Zoho divulgaron las contraseñas predeterminadas para la restauración de cuentas de dominios no autorizadas a los usuarios autenticados.
ModificadaMedia (6.5)0.74%—Cisco Identity Services Engine16/8/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to the improper storage of sensitive information within the web-based management interface. An attacker could exploit…
ModificadaMedia (6.1)3.1%—Zohocorp Manageengine Password Manager PRO11/8/202317/6/2026
Una vulnerabilidad de Cross-Site Scripting (XSS) en la función Query Report en Zoho ManageEngine Password Manager Pro versión 11001, permite a atacantes remotos ejecutar código arbitrario y robar cookies a través de un payload JavaScript manipulado.
ModificadaMedia (4.4)0.20%—Intel Converged Security Management Engine Firmware11/8/202317/6/2026
La validación de entrada inadecuada en el firmware de algunos Intel(R) Converged Security and Management Engine anteriores a las versiones 15.0.45 y 16.1.27 puede permitir que un usuario con privilegios habilite potencialmente la denegación de servicio mediante acceso local.
ModificadaAlta (7.5)0.66%—Intel Converged Security Management Engine Firmware11/8/202317/6/2026
La validación de entrada inadecuada en algunos firmware para Intel(R) AMT e Intel(R) Standard Manageability antes de las versiones 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45 y 16.1.27 en Intel (R) CSME puede permitir que un usuario no autenticado habilite potencialmente la denegación de servicio a través…
ModificadaAlta (7.8)0.15%—Intel Converged Security Management Engine Firmware11/8/202317/6/2026
Un control de acceso inadecuado en el instalador del software Intel(R) CSME anterior a la versión 2239.3.7.0 puede permitir que un usuario autenticado habilite potencialmente una escalada de privilegios mediante acceso local.
ModificadaMedia (6.1)2.3%—Zohocorp Manageengine Applications Manager10/8/202317/6/2026
Zoho ManageEngine Applications Manager through 16530 allows reflected XSS while logged in.
ModificadaAlta (7.5)3.9%—Zohocorp Manageengine Adaudit Plus7/8/202317/6/2026
The event analysis component in Zoho ManageEngine ADAudit Plus 7.1.1 allows an attacker to bypass audit detection by creating or renaming user accounts with a "$" symbol suffix. NOTE: the vendor states "We do not consider this as a security bug and it's an expected behaviour."
ModificadaMedia (6.5)3.7%—Zohocorp Manageengine Admanager Plus4/8/202317/6/2026
ADManager Plus de ManageEngine de Zoho a través de 7201 permiten a los usuarios autenticados hacerse cargo de la cuenta de otro usuario a través de la divulgación de información sensible.
ModificadaAlta (8.8)1.1%—Zohocorp Manageengine Network Configuration Manager4/8/202317/6/2026
Se ha descubierto un problema en Network Configuration Manager 12.6.165 de ManageEngine de Zoho. El WebSocket endpoint permite Cross-site WebSocket hijacking.
ModificadaMedia (5.4)2.2%—Zohocorp Manageengine Supportcenter Plus28/7/202317/6/2026
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
ModificadaMedia (6.5)0.68%—Tdengine25/7/202317/6/2026
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a patch for this issue.
ModificadaMedia (5.4)0.36%—Nesote Inout Search Engine AI Edition16/7/202317/6/2026
A vulnerability was found in Nesote Inout Search Engine AI Edition 1.1. It has been classified as problematic. This affects an unknown part of the file /index.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this…
ModificadaCrítica (9.8)1.1%—Extremenetworks IQ Engine15/7/202317/6/2026
IQ Engine before 10.6r1 on Extreme Network AP devices has a Buffer Overflow in the implementation of the CAPWAP protocol that may be exploited to obtain elevated privileges to conduct remote code execution. Access to the internal management interface/subnet is required to conduct the exploit.
ModificadaAlta (7.5)0.56%—Bitdefender Engines14/7/202317/6/2026
An out-of-bounds write vulnerability in Bitdefender Engines on Windows causes the engine to crash. This issue affects Bitdefender Engines version 7.94791 and lower.
ModificadaAlta (7.5)0.57%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server information leak of configuration data when an error is generated in response to a specially crafted message. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Server or Console Station DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.66%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a heap overflow which could occur when handling a specially crafted message
ModificadaAlta (7.5)0.65%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server DoS due to heap overflow occurring during the handling of a specially crafted message for a specific configuration operation. See Honeywell Security Notification for recommendations on upgrading and versioning.
ModificadaAlta (7.5)0.60%—Honeywell Experion ServerHoneywell Experion StationHoneywell Engineering StationHoneywell Direct Station13/7/202317/6/2026
Experion server may experience a DoS due to a stack overflow when handling a specially crafted message.
ModificadaAlta (7)0.27%—Microsoft Malware Protection Engine11/7/202317/6/2026
Microsoft Defender Elevation of Privilege Vulnerability
ModificadaAlta (8.8)0.27%—Wpengine PHP Compatibility Checker11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Engine PHP Compatibility Checker plugin <= 1.5.2 versions.
ModificadaMedia (5.4)1.9%—Zohocorp Manageengine Adaudit Plus7/7/202317/6/2026
Zoho ManageEngine ADAudit Plus before 7100 allows XSS via the username field.
ModificadaMedia (5.4)3.5%—Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus7/7/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
ModificadaCrítica (9)0.94%—Chatengine Project Chatengine6/7/202317/6/2026
Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code.