Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

22.747 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.7)0.21%—Hcltech Bigfix Service Management1/10/20266/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability the application returns sensitive information in error messages when invalid inputs are sent to certain API endpoints . This information could enable an attacker to facilitate further attacks.
AnalizadaMedia (5.3)0.24%—Hcltech Bigfix Service Management1/10/20266/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.
En análisisMedia (4.3)0.16%—HCL Bigfix Service ManagementAI1/10/20261/10/2026
HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems.
Pendiente de análisisAlta (7.5)0.33%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service…
Pendiente de análisisCrítica (9.8)0.44%—Fortra Core Privileged Access ManagerAI1/10/20261/10/2026
Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.
AplazadaBaja (2.1)0.33%—Itsourcecode Leave Management SystemAI1/10/20261/10/2026
A flaw has been found in itsourcecode Leave Management System 1.0. This vulnerability affects unknown code of the file /module/leave/controller.php. Executing a manipulation of the argument LEAVEID can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
AplazadaMedia (6.3)0.25%—Wedevs WP Project ManagerAI1/10/20261/10/2026
Subscriber Broken Access Control in WP Project Manager <= 4.0.7 versions.
Pendiente de análisisAlta (7.9)0.07%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the…
Pendiente de análisisCrítica (9.1)0.98%—Fortra Boks ManagerAI1/10/20261/10/2026
Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on the BoKS Master. BCC and WSI provide…
AnalizadaMedia (5.3)0.24%—Hcltech Bigfix Service Management1/10/20265/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints return sensitive data. This information could enable an attacker to launch further, more serious attacks.
AnalizadaAlta (7.4)0.15%—Hcltech Bigfix Service Management1/10/20265/10/2026
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
AnalizadaMedia (5.3)0.24%—Hcltech Bigfix Service Management1/10/20265/10/2026
HCL BigFix Service Management is affected by an Information Disclosure vulnerability, which could allow an unauthenticated attacker to analyze publicly accessible JavaScript files, enabling the discovery of hidden administrative API endpoints for further targeted exploitation.
AnalizadaBaja (2.2)0.06%—Hcltech Bigfix Service Management1/10/20265/10/2026
HCL BigFix Service Management is affected by an Insecure Cookie Attribute Configuration vulnerability, which could allow an attacker to exploit missing security attributes such as SameSite, HttpOnly, Secure, and restrictive Paths, enabling Cross-Site Request Forgery (CSRF), session hijacking via Cross-Site Scripting…
AnalizadaAlta (7.2)0.20%—Hcltech Bigfix Service Management1/10/20265/10/2026
HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject and store malicious scripts within the application that execute when a victim views the affected page, enabling session hijacking and the theft of sensitive data.
AplazadaMedia (6.4)0.20%—Download ManagerAI1/10/20261/10/2026
The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue,…
AplazadaBaja (2.1)0.20%—Itsourcecode Leave Management SystemAI1/10/20261/10/2026
A vulnerability has been found in itsourcecode Leave Management System 1.0. The affected element is an unknown function of the file /module/leavetype/controller.php. Such manipulation of the argument LEAVTID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and…
AplazadaBaja (2.1)0.37%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A security vulnerability has been detected in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This impacts an unknown function of the file /admin/ of the component Admin Area. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed…
AplazadaMedia (5.5)0.33%—Adithyayelloju Restaurant Management SystemAI30/9/202630/9/2026
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The…
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisMedia (6.7)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisMedia (6.7)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Pendiente de análisisAlta (7.8)0.13%—Nvidia Vgpu Virtual GPU ManagerAI30/9/20261/10/2026
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.