Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
11.986 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience Manager | 14/7/2026 | 28/8/2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must… | |
| Analizada | Media (5.4) | 0.36% | — | Adobe Experience Manager | 14/7/2026 | 28/8/2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must… | |
| Analizada | Alta (8.6) | 0.89% | — | Adobe Experience Manager | 14/7/2026 | 28/8/2026 | Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user… | |
| Analizada | Alta (8.8) | 0.78% | 💥 PoC | Microsoft Configuration Manager 2503Microsoft Configuration Manager 2509Microsoft Configuration Manager 2603 | 14/7/2026 | 30/7/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | |
| Analizada | Alta (8.8) | 0.37% | — | Microsoft PC Manager | 14/7/2026 | 21/7/2026 | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.37% | — | Microsoft PC Manager | 14/7/2026 | 17/7/2026 | Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. | |
| Pendiente de análisis | Alta (7.2) | 0.44% | — | Rockwellautomation ThinmanagerAI | 14/7/2026 | 14/7/2026 | A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory. | |
| Analizada | Media (4.9) | 0.26% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if… | |
| Analizada | Media (5.1) | 0.26% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This… | |
| Analizada | Media (5.3) | 0.17% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0… | |
| Analizada | Alta (8.2) | 0.22% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check. | |
| Analizada | Alta (8.7) | 0.32% | — | Sonatype Nexus Repository Manager | 14/7/2026 | 22/9/2026 | A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user… | |
| Aplazada | Media (5.3) | 0.29% | — | Magepeopleteam CAR Rental ManagerAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7. | |
| Aplazada | Media (5.4) | 0.29% | — | Wpexperts License Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17. | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpinventory WP Inventory ManagerAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP Inventory Manager wp-inventory-manager allows Blind SQL Injection.This issue affects WP Inventory Manager: from n/a through <= 2.4.0. | |
| Aplazada | Alta (8.8) | 0.46% | — | Marcus Events ManagerAI | 13/7/2026 | 13/7/2026 | Deserialization of Untrusted Data vulnerability in Marcus (aka @msykes) Events Manager events-manager allows Object Injection.This issue affects Events Manager: from n/a through <= 7.3.6. | |
| Aplazada | Media (6.5) | 0.33% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking and Rental Manager: from n/a through <= 2.6.9. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpswings Event Tickets Manager FOR WoocommerceAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in WP Swings Event Tickets Manager for WooCommerce event-tickets-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Event Tickets Manager for WooCommerce: from n/a through <= 1.5.5. | |
| Aplazada | Alta (7.1) | 0.25% | — | Webcodingplace Real Estate Manager PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3. | |
| Aplazada | Media (6.4) | 0.16% | — | Tencent PC ManagerAI | 13/7/2026 | 15/7/2026 | A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high… | |
| Analizada | Alta (8.5) | 0.32% | — | Dell Powerflex Manager | 10/7/2026 | 16/7/2026 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and… | |
| Analizada | Alta (7.7) | 0.37% | — | Dell Powerflex Manager | 10/7/2026 | 16/7/2026 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Crítica (9.1) | 2.0% | — | Dell Powerflex Manager | 10/7/2026 | 16/7/2026 | Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary… | |
| Aplazada | Media (5.8) | 0.14% | — | Samsung KnoxguardmanagerAI | 10/7/2026 | 10/7/2026 | Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | |
| Aplazada | Media (6.4) | 0.35% | — | Download ManagerAI | 9/7/2026 | 9/7/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… |