Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)2.0%—Zohocorp Manageengine Admanager Plus7/2/201817/6/2026
/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.
ModificadaMedia (4.3)3.6%—Zohocorp Manageengine Admanager Plus11/3/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ZOHO ManageEngine ADManager Plus before 6.2 Build 6270 allow remote attackers to inject arbitrary web script or HTML via the (1) technicianSearchText parameter to the Help Desk Technician page or (2) rolesSearchText parameter to the Help Desk Roles.
ModificadaAlta (9.3)17%💥 ExploitFreedownloadmanager Free Download Manager18/3/201417/6/2026
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download…
ModificadaMedia (6.8)0.95%—Lesterchan Wp-downloadmanager19/4/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.
ModificadaMedia (4.3)1.6%💥 ExploitManageengine Admanager Plus13/2/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do.
ModificadaMedia (4.3)3.2%—Zohocorp Manageengine Admanager Plus23/11/201116/6/2026
Cross-site scripting (XSS) vulnerability in jsp/admin/tools/remote_share.jsp in ManageEngine ADManager Plus 4.4.0 allows remote attackers to inject arbitrary web script or HTML via the computerName parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaAlta (10)8.0%—Ioquake3 EngineTremulousIourbanterrorWorldofpadman World OF Padman9/8/201116/6/2026
The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL…
ModificadaAlta (10)8.7%—Ioquake3 EngineOpenarenaSmokin-guns Smokin' GunsTremulous+24/8/201116/6/2026
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted…
ModificadaAlta (7.5)4.2%—Ioquake3 EngineOpenarenaWorldofpadman World OF Padman4/8/201116/6/2026
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.
ModificadaAlta (7.1)1.7%—Freedownloadmanager Free Download Manager17/5/201016/6/2026
Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
ModificadaAlta (10)6.4%—Freedownloadmanager Free Download Manager17/5/201016/6/2026
Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect.
ModificadaAlta (7.5)0.97%💥 ExploitE-topbiz Admanager24/2/200916/6/2026
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL commands via the group parameter.
ModificadaMedia (6.5)0.86%💥 ExploitFormfields Adman16/2/200916/6/2026
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter.
ModificadaMedia (5)2.6%💥 ExploitDotnetindex Ikon Admanager16/12/200816/6/2026
Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb.
ModificadaMedia (5.8)1.9%💥 ExploitGradman23/1/200816/6/2026
Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter, a different vector than CVE-2008-0361.
ModificadaMedia (4.3)2.8%💥 ExploitInstituto Politicnico Nacional Gradman18/1/200816/6/2026
Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter.
ModificadaMedia (4.3)1.2%—Brain Book Software Adman26/7/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in login.php in AdMan 1.0.20051202 FF 3 patch and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.
ModificadaBaja (2.6)1.2%—Site Trade ST Admanager Lite15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in publish.php in ST AdManager Lite allow remote attackers to inject arbitrary web script or HTML via the (1) title, (2) description, (3) article, (4) bio, and (5) name parameters.
ModificadaAlta (7.5)1.3%💥 ExploitBrain Book Software Adman24/3/200616/6/2026
SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute arbitrary SQL commands via the transactions_offset parameter.
ModificadaMedia (5)1.5%—Brain Book Software Adman24/3/200616/6/2026
AdMan 1.0.20051221 and earlier allows remote attackers to obtain the full path via (1) a blank campaignId parameter to editCampaign.php and (2) a blank schemeId parameter to viewPricingScheme.php.
Orbitaley — Vulnerabilidades