Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2650 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Crocoblock Jetengine FOR Elementor10/4/202317/6/2026
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
ModificadaMedia (4.8)0.39%—Vikwp Vikbooking Hotel Booking Engine & PMS6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in E4J s.R.L. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.11 versions.
ModificadaAlta (7.5)78%—Zohocorp Manageengine Adselfservice Plus5/4/202317/6/2026
Zoho ManageEngine ADSelfService Plus before 6218 allows anyone to conduct a Denial-of-Service attack via the Mobile App Authentication API.
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaAlta (7.8)0.20%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.20%—Cisco Evolved Programmable Network ManagerCisco Identity Services EngineCisco Prime Infrastructure5/4/202317/6/2026
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restricted shell and gain root privileges on the underlying operating system. For more…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6)0.75%—Cisco Identity Services Engine5/4/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information, conduct a server-side request forgery (SSRF) attack through an affected device, or negatively impact the responsiveness of the web-based…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (6.7)0.45%—Cisco Identity Services Engine5/4/202317/6/2026
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid Administrator…
ModificadaMedia (5.4)20%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager PlusZohocorp Manageengine Opmanager MSP30/3/202317/6/2026
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
ModificadaAlta (8.8)2.9%💥 PoCCocos-engine27/3/202317/6/2026
Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github repo for Cocos Engine the `web-interface-check.yml` was subject to command injection. The `web-interface-check.yml` was triggered when a pull request was opened or updated and contained the user…
ModificadaCrítica (9.1)3.1%—Zohocorp Manageengine Adselfservice Plus23/3/202317/6/2026
Zoho ManageEngine ADSelfService Plus through 6203 is vulnerable to a brute-force attack that leads to a password reset on IDM applications.
ModificadaAlta (7.5)1.3%—Hasura Graphql Engine14/3/202317/6/2026
Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted Hasura Projects with deployments that…
ModificadaMedia (6.3)0.26%—Microsoft Malware Protection Engine14/3/202317/6/2026
Microsoft Defender Elevation of Privilege Vulnerability
ModificadaAlta (7.5)34%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus6/3/202317/6/2026
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).
ModificadaMedia (6.5)6.3%—Zohocorp Manageengine AssetexplorerZohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus6/3/202317/6/2026
ManageEngine ServiceDesk Plus through 14104, ServiceDesk Plus MSP through 14000, Support Center Plus through 14000, and Asset Explorer through 6987 allow privilege escalation via query reports.
ModificadaMedia (5.3)0.43%—Blogengine.net6/3/202317/6/2026
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
ModificadaMedia (5.4)0.36%—Blogengine.net6/3/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post.
ModificadaMedia (5.4)0.38%—Blogengine.net6/3/202317/6/2026
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an upload of a specially crafted file.
ModificadaMedia (6.1)0.74%—Cisco Identity Services Engine1/3/202317/6/2026
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation…
ModificadaAlta (8.8)8.7%—Zohocorp Manageengine Desktop Central25/2/202317/6/2026
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName to AgentLogUploadServlet. A remote, authenticated attacker could upload arbitrary code that would be executed when Desktop Central is restarted. (The attacker could authenticate by exploiting…
ModificadaAlta (8.8)0.63%—Orangelab Imagemagick Engine10/2/202317/6/2026
El complemento ImageMagick Engine para WordPress es vulnerable a la deserialización de entradas que no son de confianza a través del parámetro 'cli_path' en versiones hasta la 1.7.5 incluida. Esto hace posible que usuarios no autenticados llamen archivos usando un contenedor PHAR, siempre que puedan engañar a un…
ModificadaAlta (8.8)1.4%—Expressionengine9/2/202317/6/2026
In ExpressionEngine before 7.2.6, remote code execution can be achieved by an authenticated Control Panel user.
Orbitaley — Vulnerabilidades