Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.67%—Wplearnmanager WP Learn ManagerAI8/7/20268/7/2026
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins…
AplazadaAlta (8.5)0.17%💥 PoCMSI Feature ManagerAIMSI Kerncorelib64AI7/7/202610/7/2026
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can…
AplazadaAlta (8.7)0.39%💥 PoCNajeebmedia Frontend File ManagerAI7/7/20267/7/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the…
AnalizadaAlta (8.6)0.56%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/7/20269/7/2026
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful…
Pendiente de análisisMedia (4.8)0.31%—Uniflow Universal Login ManagerAI6/7/20266/7/2026
uniFLOW Universal Login Manager (ULM) Standalone contains an information disclosure vulnerability that may allow an authenticated administrator to access sensitive configuration information through the ULM Remote User Interface (RUI). Exploitation requires administrative privileges and may disclose configuration data…
AnalizadaMedia (6.1)0.25%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/7/20266/10/2026
El software acepta entrada proporcionada por el usuario a través de un parámetro de URL sin una codificación de salida adecuada antes de reflejarla de vuelta al navegador del usuario. Esta condición permite a un atacante inyectar contenido de script malicioso en páginas servidas por la aplicación. Al aprovechar esta…
AplazadaCrítica (9.1)1.4%—FileorganizerAIFile ManagerAIAdvancedfilemanager Advanced File ManagerAIFilemanagerpro File Manager PROAI6/7/20266/7/2026
El plugin FileOrganizer para WordPress anterior a la versión 1.1.9, el plugin Advanced File Manager para WordPress anterior a la versión 5.4.12, el plugin File Manager Pro para WordPress anterior a la versión 2.1.1 y el plugin File Manager para WordPress anterior a la versión 8.0.4 no escapan correctamente un…
AnalizadaMedia (5.3)0.30%—Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+14/7/20269/7/2026
The silent Just-In-Time (JIT) provisioning feature in federated authentication implementations fails to properly segregate user roles during account creation when a federated user shares a username with a local user. This allows the provisioning process to overwrite existing roles of local users with roles assigned to…
AnalizadaAlta (7.3)0.27%—Wso2 API ManagerWso2 Identity Server4/7/20266/10/2026
En despliegues multi-inquilino, el mecanismo de gestión de consentimiento de aplicaciones no logra aislar correctamente los ámbitos de consentimiento entre inquilinos. El consentimiento otorgado por un usuario para una aplicación SaaS específica dentro de un inquilino puede aplicarse incorrectamente a aplicaciones…
AplazadaAlta (8.5)0.15%—Asus Business ManagerAI3/7/202617/9/2026
External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information.
AplazadaAlta (7.1)0.13%—Permalink ManagerAI2/7/20262/7/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.
AplazadaAlta (7.1)0.25%—Internal Links ManagerAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in Internal Links Manager <= 3.0.3 versions.
AnalizadaAlta (7.5)0.65%—Cisco Catalyst CenterCisco Catalyst Center Global Manager1/7/202617/9/2026
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
AplazadaMedia (6.4)0.36%—Download ManagerAI1/7/20261/7/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
Pendiente de análisisMedia (5.6)0.11%—BMC Control-m Enterprise ManagerAI1/7/20261/7/2026
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported…
Pendiente de análisisAlta (8.9)0.42%—BMC Control-m ServerAIBMC Control-m Enterprise ManagerAI1/7/20261/7/2026
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended…
AnalizadaCrítica (9.1)0.41%—IBM Business Automation Manager30/6/20262/7/2026
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AplazadaCrítica (9.1)0.66%💥 PoCAlexantr FilemanagerAI29/6/202630/6/2026
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component
AplazadaAlta (7.5)0.35%—Apcu ManagerAI29/6/202629/6/2026
The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is enabled, cache keys derived from unsanitised user input (e.g. a transient name created by another…
AplazadaAlta (8.1)0.60%—Najeebmedia Frontend File ManagerAI28/6/202629/6/2026
The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase…
AnalizadaAlta (7.2)0.50%—Devolutions Remote Desktop Manager26/6/202629/6/2026
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing…
AplazadaMedia (5.3)0.29%—Booking AND Rental ManagerAI26/6/202629/6/2026
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
AplazadaMedia (6.5)0.30%—Wpaffiliatemanager Affiliates ManagerAI26/6/202629/6/2026
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
AnalizadaCrítica (10)0.39%—Wso2 API Manager26/6/202627/6/2026
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an attacker to manipulate WS-Addressing headers to specify arbitrary destinations for server-initiated requests. Successful…
AplazadaMedia (6.5)0.47%💥 PoCNajeebmedia Frontend File ManagerAI26/6/202626/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin…