Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

11.986 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.55%—Wpusermanager WP User ManagerAI15/6/202617/6/2026
Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.
AplazadaAlta (7.5)0.35%—Event Tickets ManagerAI15/6/202617/6/2026
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
Pendiente de análisisMedia (6.5)0.23%—Nginx Proxy ManagerAI15/6/202617/6/2026
Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request.
AnalizadaMedia (6.5)28%⚠ Explotación activa💥 PoCCisco Catalyst Sd-wan Manager15/6/202624/7/2026
Una vulnerabilidad en la interfaz de usuario web de Cisco Catalyst SD-WAN Manager, anteriormente SD-WAN vManage, podría permitir a un atacante remoto autenticado crear o sobrescribir cualquier archivo en el sistema de archivos de un sistema afectado. Esta vulnerabilidad existe porque el software afectado no valida…
AnalizadaAlta (8.8)1.0%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client…
AnalizadaCrítica (9.8)1.5%—Fortra Core Privileged Access Manager Server15/6/202628/7/2026
Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
AplazadaAlta (8.8)0.30%—404 Redirection ManagerAI15/6/202617/6/2026
The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate…
AplazadaCrítica (9.3)0.71%—Responsivefilemanager Responsive FilemanagerAI15/6/202617/6/2026
Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0
AplazadaAlta (7.4)0.26%—Avira Password ManagerAIMozilla FirefoxAI12/6/202623/7/2026
Vulnerabilidad de revelación de información en Avira Password Manager cuando se usa con Mozilla Firefox puede permitir a un atacante remoto que opera un iframe de origen cruzado obtener credenciales autorrellenadas para la página web principal mediante una selección incorrecta del campo de autorrelleno. Este problema…
AnalizadaMedia (4.4)0.42%—Metal3 Ip-address-manager12/6/202617/6/2026
IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the…
AnalizadaAlta (8.7)0.63%—Paloaltonetworks Idira Privileged Access Manager Vault12/6/20267/7/2026
Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized…
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19
AnalizadaAlta (8.7)0.81%—Paloaltonetworks Idira Privileged Session Manager FOR SSH11/6/202623/6/2026
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18
AnalizadaAlta (8.7)0.72%—Paloaltonetworks Idira Privileged Session Manager11/6/202623/6/2026
Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent…
AnalizadaAlta (8.4)0.51%—Paloaltonetworks Idira Secrets ManagerPaloaltonetworks Idira Secrets Manager Credential Providers11/6/202622/6/2026
Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS).…
AnalizadaCrítica (9.1)0.73%—Paloaltonetworks Idira Secrets Manager Edge11/6/202622/6/2026
Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauthenticated attacker could exploit this by submitting a specially crafted request. Under specific circumstances, this could allow the attacker to manipulate internal…
AnalizadaAlta (8.9)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow…
AnalizadaAlta (8.7)0.63%—Sonatype Nexus Repository Manager11/6/202621/7/2026
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
Pendiente de análisisAlta (8.5)0.15%—Lenovo Accessories AND Display Manager FOR EnterpriseAI10/6/202617/6/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
ModificadaAlta (7.8)0.30%—Microsoft PC Manager9/6/202623/7/2026
Resolución de enlaces incorrecta antes del acceso a archivos (seguimiento de enlaces) en Microsoft PC Manager permite a un atacante autorizado elevar privilegios localmente.
AnalizadaAlta (7.8)0.37%—Microsoft PC Manager9/6/202623/7/2026
Resolución de enlaces incorrecta antes del acceso a archivos ('seguimiento de enlaces') en Microsoft PC Manager permite a un atacante autorizado elevar privilegios localmente.
AnalizadaMedia (4.8)0.41%—Adobe Experience Manager9/6/202628/8/2026
Las versiones LTS SP1, 6.5.24.0 y anteriores de Adobe Experience Manager Forms JEE están afectadas por una vulnerabilidad de cross-site scripting (XSS) almacenado que podría ser explotada por un atacante con altos privilegios para inyectar scripts maliciosos en campos de formulario vulnerables. JavaScript malicioso…
AnalizadaAlta (8)0.57%—Adobe Experience Manager9/6/202628/8/2026
Las versiones LTS SP1, 6.5.24.0 y anteriores de Adobe Experience Manager Forms JEE están afectadas por una vulnerabilidad de cross-site scripting (XSS) reflejado. Un atacante podría explotar esta vulnerabilidad para inyectar scripts maliciosos en una página web, obteniendo potencialmente acceso elevado o control sobre…
AnalizadaCrítica (9.3)0.74%—Adobe Experience Manager9/6/202628/8/2026
Las versiones LTS SP1, 6.5.24.0 y anteriores de Adobe Experience Manager Forms JEE están afectadas por una vulnerabilidad de cross-site scripting (XSS) almacenado que podría ser explotada por un atacante para inyectar scripts maliciosos en campos de formulario vulnerables. JavaScript malicioso podría ejecutarse en el…