Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

11.967 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
En análisisMedia (5.3)0.26%—Ordasoft Vehicle ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the…
En análisisCrítica (9.3)0.28%💥 PoCOrdasoft Vehicle ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing…
En análisisMedia (5.3)0.26%—Ordasoft Real Estate ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same…
En análisisCrítica (9.3)0.28%💥 PoCOrdasoft Real Estate ManagerAI28/9/202630/9/2026
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field…
AplazadaMedia (5.6)0.11%—ABB Protection AND Control IED ManagerAI28/9/202628/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
AplazadaAlta (7.1)0.09%—ABB Protection AND Control IED ManagerAI28/9/202628/9/2026
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
AplazadaMedia (5.4)0.17%—Blacklist Manager FOR WoocommerceAI28/9/202628/9/2026
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
AplazadaAlta (8.8)0.28%—Download ManagerAI27/9/202628/9/2026
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects…
AplazadaAlta (8.4)0.29%—Getgrav Grav Plugin DatamanagerAI26/9/202630/9/2026
The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries in the item-detail view (admin/templates/partials/item.html.twig) without escaping, applying Twig's `raw` filter — in some cases after a striptags('<br>') call that PHP's strip_tags() bypasses by…
AplazadaAlta (7.5)0.22%—File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI26/9/202628/9/2026
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the…
AplazadaMedia (5.9)0.22%—File ManagerAI26/9/202628/9/2026
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on…
AplazadaAlta (7.8)0.19%—Networkmanager VpncAI25/9/202630/9/2026
A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by injecting a newline character into the CA-File path. This manipulation allows the user to execute arbitrary commands as the root user, leading to local privilege escalation.
AplazadaAlta (7.8)0.19%—Networkmanager-vpncAI25/9/202630/9/2026
A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to root. By injecting a newline character into the VPN username field, an attacker can manipulate the vpnc configuration to execute an arbitrary program with root privileges when the malicious VPN…
AplazadaAlta (7.8)0.20%—Networkmanager FortisslvpnAI25/9/202630/9/2026
A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service improperly handles carriage-return/line-feed (CR/LF) characters in VPN connection profile credentials. A local unprivileged user can exploit this by crafting a malicious VPN profile to inject…
AplazadaAlta (7.8)0.10%—Networkmanager SstpAI25/9/202630/9/2026
A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit this vulnerability by embedding special characters, known as shell metacharacters, into VPN connection profile fields such as CA certificate or proxy settings. These unescaped characters are then…
AplazadaAlta (7.8)0.14%—Networkmanager-iodineAI25/9/202630/9/2026
A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedding shell metacharacters (special characters that can execute commands) in the…
AplazadaMedia (4.3)0.18%—Events ManagerAI24/9/202624/9/2026
The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending or trashed event and venue content, including full street addresses.
AplazadaBaja (2.7)0.17%—Events ManagerAI24/9/202624/9/2026
The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any ticket on the site to their own event.
AplazadaAlta (7.2)0.40%—Reycob Shop ManagerAI23/9/202623/9/2026
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
AplazadaMedia (5.3)0.22%—Wpusermanager WP User ManagerAI23/9/202623/9/2026
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
Pendiente de análisisAlta (8.5)0.18%—Networkmanager-l2tpAIPppdAI23/9/202624/9/2026
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in…
En análisisMedia (6.2)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
En análisisAlta (8.2)0.30%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
En análisisMedia (4.4)0.09%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
En análisisAlta (7.3)0.22%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI23/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool…