Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
11.991 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.5% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods. | |
| Analizada | Crítica (9.1) | 0.85% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. | |
| Analizada | Alta (7.2) | 0.53% | 💥 PoC | Devcode Openstamanager | 4/5/2026 | 17/6/2026 | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php) | |
| Aplazada | Media (6.5) | 0.34% | — | Najeebmedia Frontend File ManagerAI | 3/5/2026 | 17/6/2026 | During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user… | |
| Aplazada | Alta (8.6) | 0.15% | — | Freedownloadmanager Free Download ManagerAI | 29/4/2026 | 17/6/2026 | Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads… | |
| Aplazada | Media (4.3) | 0.14% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 29/4/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <=… | |
| Aplazada | Alta (8.8) | 0.59% | — | Highland Software Custom Role ManagerAI | 27/4/2026 | 17/6/2026 | The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated… | |
| Aplazada | Media (6.8) | 0.13% | — | Drive Power ManagerAI | 26/4/2026 | 17/6/2026 | Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition. | |
| Aplazada | Media (6.5) | 0.22% | — | Magepeople Taxi Booking Manager FOR WoocommerceAI | 23/4/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0. | |
| Aplazada | Alta (8.5) | 0.62% | 💥 PoC | Stig ManagerAI | 23/4/2026 | 17/6/2026 | STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in `src/init.js` and `public/reauth.html`. During… | |
| Modificada | Media (4.8) | 0.19% | — | IBM Guardium KEY Lifecycle Manager | 23/4/2026 | 17/6/2026 | IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines… | |
| Analizada | Alta (8.6) | 0.19% | — | Lizardsystems Terminal Services Manager | 22/4/2026 | 17/6/2026 | Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH… | |
| Aplazada | Media (4.3) | 0.41% | — | Table ManagerAI | 22/4/2026 | 17/6/2026 | The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0 via the 'table_manager' shortcode. The shortcode handler `tablemanager_render_table_shortcode()` takes a user-controlled `table` attribute, applies only `sanitize_key()` for sanitization,… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Analizada | Media (5.9) | 0.23% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Identity Manager… | |
| Analizada | Alta (7.5) | 0.47% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector.… | |
| Analizada | Media (5.9) | 0.33% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Crítica (9.1) | 0.43% | — | Oracle Identity Manager Connector | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful… | |
| Analizada | Media (6.1) | 0.24% | — | Oracle Identity Manager | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.… | |
| Analizada | Crítica (9.1) | 0.49% | — | Oracle Enterprise Manager Base Platform | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager… | |
| Aplazada | Baja (3.2) | 0.13% | — | PcmanagerAI | 21/4/2026 | 17/6/2026 | PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability |