Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.1%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more…
ModificadaAlta (7.2)1.1%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more…
ModificadaBaja (3.8)0.37%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities,…
ModificadaMedia (6.5)0.84%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these…
ModificadaMedia (6.5)0.84%—Cisco Identity Services Engine18/5/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insufficient input validation. An attacker could exploit these…
ModificadaAlta (8.8)0.61%—Intel Quickassist Technology Engine10/5/202317/6/2026
Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaMedia (5.3)0.70%—Next-engine Next Engine Integration10/5/202317/6/2026
Authentication bypass vulnerability in NEXT ENGINE Integration Plugin (for EC-CUBE 2.0 series) all versions allows a remote unauthenticated attacker to alter the information stored in the system.
ModificadaMedia (6.5)1.3%—Socket Engine.io8/5/202317/6/2026
Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Socket.IO. An uncaught exception vulnerability was introduced in version 5.1.0 and included in version 4.1.0 of the `socket.io` parent package. Older versions are not impacted. A specially crafted HTTP…
ModificadaAlta (8.8)0.87%—Avirato Hotels Online Booking Engine8/5/202317/6/2026
The Avirato hotels online booking engine WordPress plugin through 5.0.5 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks.
ModificadaAlta (8.8)82%—Zohocorp Manageengine Opmanager4/5/202317/6/2026
Zoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.
ModificadaAlta (7.8)0.81%—Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Pam360Zohocorp Manageengine Password Manager PRO26/4/202317/6/2026
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP) build 4309, ManageEngine Password Manager Pro, and ManageEngine PAM360. These credentials could allow a malicious actor to modify configuration data that would escalate their permissions from that of a low-privileged user to…
ModificadaMedia (4.9)3.0%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus26/4/202317/6/2026
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
ModificadaMedia (6.1)9.4%—Zohocorp Manageengine Applications Manager26/4/202317/6/2026
Zoho ManageEngine Applications Manager before 16400 allows proxy.html DOM XSS.
ModificadaMedia (6.5)0.55%—Northern.tech Cfengine26/4/202317/6/2026
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
ModificadaMedia (5.3)0.57%—Juniper Appid Service SigpackJuniper Jdpi-decoder EngineJuniper Junos17/4/202317/6/2026
—
ModificadaMedia (5.4)1.8%💥 ExploitX2engine X2crm15/4/202317/6/2026
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Create Action function, aka an index.php/actions/update URI.
ModificadaMedia (5.4)1.8%💥 ExploitX2engine X2crm15/4/202317/6/2026
X2CRM Open Source Sales CRM 6.6 and 6.9 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the adin/importModels Import Records Model field (model parameter). This vulnerability allows attackers to create malicious JavaScript that will be executed by the victim user's browser.
ModificadaAlta (7.2)98%💥 ExploitZohocorp Manageengine Admanager Plus13/4/202317/6/2026
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
AnalizadaCrítica (9)1.1%—Apache Sling Engine13/4/202317/6/2026
The SlingRequestDispatcher doesn't correctly implement the RequestDispatcher API resulting in a generic type of include-based cross-site scripting issues on the Apache Sling level. The vulnerability is exploitable by an attacker that is able to include a resource with specific content-type and control the include path…
ModificadaAlta (7.5)3.0%—Microsoft Malware Protection Engine11/4/202317/6/2026
Microsoft Defender Denial of Service Vulnerability
ModificadaMedia (6.1)99%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Stored Cross site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager through 16340 allows an unauthenticated user to inject malicious javascript on the incorrect login details page.
ModificadaMedia (6.5)3.2%—Zohocorp Manageengine Applications Manager11/4/202317/6/2026
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
ModificadaMedia (5.4)0.59%—Pega Synchronization Engine10/4/202317/6/2026
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
ModificadaMedia (6.5)1.4%—Pega Synchronization Engine10/4/202317/6/2026
A user with a compromised configuration can start an unsigned binary as a service.
ModificadaAlta (7.8)0.17%—Pega Synchronization Engine10/4/202317/6/2026
A user with non-Admin access can change a configuration file on the client to modify the Server URL.