Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
591 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Wpexperts License Manager FOR WoocommerceAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Reflected XSS.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.9. | |
| Aplazada | Media (6.1) | 0.33% | — | Digital License ManagerAI | 25/3/2025 | 17/6/2026 | The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Media (6.1) | 0.27% | — | Reprisesoftware Reprise License Manager | 3/3/2025 | 17/6/2026 | Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter. | |
| Aplazada | Media (6.1) | 0.27% | — | Quick License ManagerAI | 3/12/2024 | 17/6/2026 | The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Media (4.3) | 0.38% | — | Wpusermanager WP User Manager | 23/11/2024 | 17/6/2026 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Analizada | Media (4.3) | 0.44% | — | Wpusermanager WP User Manager | 23/11/2024 | 17/6/2026 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.18% | — | Henrik Hoff WP Course ManagerAI | 14/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Manager: from n/a through <= 1.3. | |
| Aplazada | Crítica (9.2) | 11% | — | Siemens Automation License ManagerAI | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp.… | |
| Modificada | Media (4.3) | 0.18% | — | Wpusermanager WP User Manager | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10. | |
| Analizada | Media (5.4) | 0.14% | — | Intel License Manager FOR Flexim | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (4.8) | 0.33% | — | Shawon786 House Manager | 7/8/2024 | 17/6/2026 | The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.5) | 0.39% | — | Wpexperts License Manager FOR Woocommerce | 21/6/2024 | 17/6/2026 | The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with admin dashboard access… | |
| Aplazada | Alta (8.8) | 0.48% | — | Snowsoftware Snow License ManagerAI | 14/5/2024 | 17/6/2026 | Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0. | |
| Analizada | Media (6.8) | 0.79% | — | Jenkins Subversion Partial Release Manager | 2/5/2024 | 17/6/2026 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'. | |
| Analizada | Alta (8.8) | 0.20% | — | Oracle Enterprise Manager Base Platform | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Host Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base… | |
| Aplazada | Alta (7.1) | 0.38% | — | Firassaidi Woocommerce License ManagerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firassaidi WooCommerce License Manager allows Reflected XSS.This issue affects WooCommerce License Manager: from n/a through 5.3.1. | |
| Analizada | Media (4.3) | 0.50% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build. | |
| Analizada | Media (4.3) | 0.31% | — | Jenkins Subversion Partial Release Manager | 6/3/2024 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build. | |
| Analizada | Alta (7.5) | 0.38% | — | Oracle Enterprise Manager Base Platform | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Log Management). The supported version that is affected is 13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base… | |
| Modificada | Alta (7.5) | 0.69% | — | Reprisesoftware Reprise License Manager | 3/2/2024 | 17/6/2026 | Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request. | |
| Modificada | Alta (8.8) | 1.2% | — | Reprisesoftware Reprise License Manager | 3/2/2024 | 17/6/2026 | Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack their account. | |
| Modificada | Alta (8.3) | 0.34% | — | Oracle Enterprise Manager | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability allows high privileged attacker with access to the physical communication segment attached to the… | |
| Modificada | Alta (7.2) | 0.70% | — | Wpexperts License Manager FOR Woocommerce | 30/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10. | |
| Modificada | Media (4.8) | 0.33% | — | Snowsoftware Snow License Manager | 11/8/2023 | 17/6/2026 | Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser | |
| Modificada | Alta (7.2) | 0.56% | — | Snowsoftware Snow License Manager | 11/8/2023 | 17/6/2026 | Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. |