Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
11.967 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| En análisis | Media (5.3) | 0.26% | — | Ordasoft Vehicle ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the… | |
| En análisis | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Vehicle ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing… | |
| En análisis | Media (5.3) | 0.26% | — | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same… | |
| En análisis | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field… | |
| Aplazada | Media (5.6) | 0.11% | — | ABB Protection AND Control IED ManagerAI | 28/9/2026 | 28/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14. | |
| Aplazada | Alta (7.1) | 0.09% | — | ABB Protection AND Control IED ManagerAI | 28/9/2026 | 28/9/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14. | |
| Aplazada | Media (5.4) | 0.17% | — | Blacklist Manager FOR WoocommerceAI | 28/9/2026 | 28/9/2026 | The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded. | |
| Aplazada | Alta (8.8) | 0.28% | — | Download ManagerAI | 27/9/2026 | 28/9/2026 | The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects… | |
| Aplazada | Alta (8.4) | 0.29% | — | Getgrav Grav Plugin DatamanagerAI | 26/9/2026 | 30/9/2026 | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by… | |
| Aplazada | Alta (7.5) | 0.22% | — | File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the… | |
| Aplazada | Media (5.9) | 0.22% | — | File ManagerAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on… | |
| Aplazada | Alta (7.8) | 0.19% | — | Networkmanager VpncAI | 25/9/2026 | 30/9/2026 | A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation. | |
| Aplazada | Alta (7.8) | 0.19% | — | Networkmanager-vpncAI | 25/9/2026 | 30/9/2026 | A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN… | |
| Aplazada | Alta (7.8) | 0.20% | — | Networkmanager FortisslvpnAI | 25/9/2026 | 30/9/2026 | A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject… | |
| Aplazada | Alta (7.8) | 0.10% | — | Networkmanager SstpAI | 25/9/2026 | 30/9/2026 | A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then… | |
| Aplazada | Alta (7.8) | 0.14% | — | Networkmanager-iodineAI | 25/9/2026 | 30/9/2026 | A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the… | |
| Aplazada | Media (4.3) | 0.18% | — | Events ManagerAI | 24/9/2026 | 24/9/2026 | The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses. | |
| Aplazada | Baja (2.7) | 0.17% | — | Events ManagerAI | 24/9/2026 | 24/9/2026 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event. | |
| Aplazada | Alta (7.2) | 0.40% | — | Reycob Shop ManagerAI | 23/9/2026 | 23/9/2026 | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Wpusermanager WP User ManagerAI | 23/9/2026 | 23/9/2026 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. | |
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Networkmanager-l2tpAIPppdAI | 23/9/2026 | 24/9/2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in… | |
| En análisis | Media (6.2) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. | |
| En análisis | Alta (8.2) | 0.30% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression. | |
| En análisis | Media (4.4) | 0.09% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. | |
| En análisis | Alta (7.3) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 23/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool… |