Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
11.986 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.82% | — | Dell Display AND Peripheral Manager | 25/6/2026 | 5/8/2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpexperts License Manager FOR WoocommerceAI | 25/6/2026 | 29/6/2026 | Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. | |
| Analizada | Alta (7.8) | 0.09% | — | Dell Display AND Peripheral Manager | 25/6/2026 | 10/7/2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Display AND Peripheral Manager | 25/6/2026 | 10/7/2026 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (7) | 0.10% | — | Dell Display AND Peripheral Manager | 25/6/2026 | 10/7/2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (8.2) | 0.22% | — | Microfocus Access Manager | 24/6/2026 | 29/6/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2. | |
| Analizada | Media (6.3) | 0.30% | — | Microfocus Access Manager | 24/6/2026 | 29/6/2026 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3. | |
| Aplazada | Alta (8.8) | 0.83% | — | Jenkins External Workspace Manager PluginAI | 24/6/2026 | 25/6/2026 | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code… | |
| Aplazada | Media (4.3) | 0.39% | — | Advance NAV Menu ManagerAI | 24/6/2026 | 25/6/2026 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,… | |
| Pendiente de análisis | Crítica (9) | 2.5% | 💥 PoC | Manageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI | 23/6/2026 | 24/6/2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover. | |
| Aplazada | Alta (7.5) | 0.41% | — | Najeebmedia Frontend File ManagerAI | 23/6/2026 | 23/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers. | |
| Aplazada | Media (5.4) | 0.23% | — | Najeebmedia Frontend File ManagerAI | 23/6/2026 | 23/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with… | |
| Aplazada | Alta (7.1) | 0.16% | — | Aomei Dynamic Disk ManagerAI | 21/6/2026 | 22/6/2026 | A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public… | |
| Analizada | Alta (8.8) | 0.49% | — | Cmsjunkie Classifiedsmanager | 19/6/2026 | 19/8/2026 | Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the… | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | Flexerasoftware Flexnet Manager SuiteAI | 19/6/2026 | 22/6/2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to insufficient access control. | |
| Pendiente de análisis | Alta (8.7) | 0.35% | — | Flexerasoftware Flexnet Manager SuiteAI | 19/6/2026 | 22/6/2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level. | |
| Pendiente de análisis | Crítica (9.4) | 1.3% | — | Rancher ManagerAI | 19/6/2026 | 24/6/2026 | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Server Hardware Manager | 19/6/2026 | 26/6/2026 | Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Media (5.9) | 0.27% | — | Sonatype Nexus Repository Manager | 17/6/2026 | 21/7/2026 | Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials. | |
| Modificada | Alta (8) | 0.38% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection. | |
| Modificada | Media (5.7) | 0.30% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure. | |
| Modificada | Alta (8.1) | 0.34% | — | Dell Powerflex Manager | 17/6/2026 | 25/6/2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Unauthorized access. | |
| Analizada | Media (6.3) | 0.37% | — | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+3 | 17/6/2026 | 11/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction… | |
| Modificada | Crítica (9.2) | 1.1% | 💥 PoC | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source | 17/6/2026 | 16/7/2026 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a… | |
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… |