Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

11.991 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)1.5%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
AnalizadaCrítica (9.1)0.85%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
AnalizadaAlta (8.8)1.2%—Ivanti Endpoint Manager Mobile7/5/202617/6/2026
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
AnalizadaAlta (7.2)0.53%💥 PoCDevcode Openstamanager4/5/202617/6/2026
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
AplazadaMedia (6.5)0.34%—Najeebmedia Frontend File ManagerAI3/5/202617/6/2026
During the analysis, it was identified that authenticated attackers with Subscriber-level access or higher are able to perform an Insecure Direct Object Reference (IDOR) attack. This vulnerability exists because the Frontend File Manager Plugin WordPress plugin through 23.6 does not properly validate user…
AplazadaAlta (8.6)0.15%—Freedownloadmanager Free Download ManagerAI29/4/202617/6/2026
Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads…
AplazadaMedia (4.3)0.14%—Dmitry V Barcode Scanner With Inventory AND Order ManagerAI29/4/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Cross Site Request Forgery.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <=…
AplazadaAlta (8.8)0.59%—Highland Software Custom Role ManagerAI27/4/202617/6/2026
The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated…
AplazadaMedia (6.8)0.13%—Drive Power ManagerAI26/4/202617/6/2026
Drive Power Manager 1.10 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Name field. Attackers can paste a 6000-byte payload into the Name field and click Register to trigger a denial of service condition.
AplazadaMedia (6.5)0.22%—Magepeople Taxi Booking Manager FOR WoocommerceAI23/4/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Booking Manager for WooCommerce: from n/a through 2.0.0.
AplazadaAlta (8.5)0.62%💥 PoCStig ManagerAI23/4/202617/6/2026
STIG Manager is an API and web client for managing Security Technical Implementation Guides (STIG) assessments of Information Systems. Versions 1.5.10 through 1.6.7 have a reflected Cross-Site Scripting (XSS) vulnerability in the OIDC authentication error handling code in `src/init.js` and `public/reauth.html`. During…
ModificadaMedia (4.8)0.19%—IBM Guardium KEY Lifecycle Manager23/4/202617/6/2026
IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthorized users to perform administrative operations after being demoted. Attackers could access sensitive data, modify system configurations, or change permissions for other users. The issue undermines…
AnalizadaAlta (8.6)0.19%—Lizardsystems Terminal Services Manager22/4/202617/6/2026
Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH…
AplazadaMedia (4.3)0.41%—Table ManagerAI22/4/202617/6/2026
The Table Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.0 via the 'table_manager' shortcode. The shortcode handler `tablemanager_render_table_shortcode()` takes a user-controlled `table` attribute, applies only `sanitize_key()` for sanitization,…
AnalizadaAlta (7.8)3.4%⚠ Explotación activa💥 ExploitLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AnalizadaMedia (5.9)0.23%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Microsoft Active Directory). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Identity Manager…
AnalizadaAlta (7.5)0.47%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector. Successful…
AnalizadaMedia (5.9)0.33%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector.…
AnalizadaMedia (5.9)0.33%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector. Successful…
AnalizadaCrítica (9.1)0.43%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful…
AnalizadaCrítica (9.1)0.43%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful…
AnalizadaCrítica (9.1)0.43%—Oracle Identity Manager Connector21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Identity Manager Connector. Successful…
AnalizadaMedia (6.1)0.24%—Oracle Identity Manager21/4/202617/6/2026
Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.…
AnalizadaCrítica (9.1)0.49%—Oracle Enterprise Manager Base Platform21/4/202617/6/2026
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager…
AplazadaBaja (3.2)0.13%—PcmanagerAI21/4/202617/6/2026
PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability