Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
11.991 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in a custom WAF rule file during the file upload process. | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “VS Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'aclcontrol' command | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “All” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'killsession' command | |
| Analizada | Alta (7.2) | 4.2% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Loadmaster | 20/4/2026 | 17/6/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacker with “Geo Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the 'addcountry' command | |
| Analizada | Alta (8.5) | 0.15% | — | Skygroup Skymec IT ManagerSkygroup Skysea Client View | 20/4/2026 | 17/6/2026 | SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the… | |
| Analizada | Alta (8.7) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc. When the affected device is connected to the network with the initial (factory-default) configuration, the device can be configured with the null string password. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an improper neutralization of CRLF sequences ('CRLF Injection') vulnerability. Processing some crafted configuration data may lead to arbitrary entries injected to the system configuration. | |
| Analizada | Media (5.1) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a reflected cross-site scripting vulnerability. When a user logs in to the affected device and access some crafted web page, arbitrary script may be executed on the user's browser. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue. The device configuration may be altered without authentication. | |
| Analizada | Media (6.9) | 0.60% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in packet data processing of sx_smpd. Processing a crafted packet may cause a temporary denial-of-service (DoS) condition. | |
| Analizada | Alta (7.1) | 0.46% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device without knowing the password by sending a crafted packet. | |
| Analizada | Alta (8.2) | 0.27% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a use of a broken or risky cryptographic algorithm. Information in the traffic may be retrieved via man-in-the-middle attack. | |
| Analizada | Media (6.9) | 0.40% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. use a hard-coded cryptographic key. An administrative user may be directed to apply a fake firmware update. | |
| Analizada | Media (6.9) | 0.47% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a missing authentication for critical function issue on firmware maintenance. Arbitrary file may be uploaded on the device without authentication. | |
| Analizada | Crítica (9.3) | 0.71% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a heap-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Analizada | Alta (8.7) | 0.65% | — | Silextechnology Sd-330ac FirmwareSilextechnology AMC Manager | 20/4/2026 | 17/6/2026 | SD-330AC and AMC Manager provided by silex technology, Inc. contain a stack-based buffer overflow vulnerability in processing the redirect URLs. Arbitrary code may be executed on the device. | |
| Aplazada | Baja (2.1) | 0.35% | — | Prasathmani TinyfilemanagerAI | 17/4/2026 | 17/6/2026 | A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulation of the argument uploadurl causes server-side request forgery. It is possible… | |
| Aplazada | Baja (2.1) | 0.54% | — | Prasathmani TinyfilemanagerAI | 17/4/2026 | 17/6/2026 | A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack may be performed from remote. The exploit has been made public and… | |
| Pendiente de análisis | Alta (8.1) | 2.6% | — | Zohocorp Manageengine Pam360AIZohocorp Manageengine Password Manager PROAI | 16/4/2026 | 17/6/2026 | Zohocorp ManageEngine PAM360 versions before 8531 and ManageEngine Password Manager Pro versions from 8600 to 13230 are vulnerable to Authenticated SQL injection in the query report module. | |
| Analizada | Media (6.1) | 0.23% | — | Wso2 API ManagerWso2 Identity Server | 16/4/2026 | 17/6/2026 | The authentication endpoint fails to encode user-supplied input before rendering it in the web page, allowing for script injection. An attacker can leverage this by injecting malicious scripts into the authentication endpoint. This can result in the user's browser being redirected to a malicious website, manipulation… | |
| Analizada | Alta (7.5) | 0.27% | — | Wso2 API Manager | 16/4/2026 | 17/6/2026 | The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted XML payload that exploits the unescaped external entity references. By leveraging this vulnerability, a malicious actor can read confidential files from the product's… | |
| Analizada | Media (5.4) | 0.19% | — | Wso2 API Manager | 16/4/2026 | 17/6/2026 | The WSO2 API Manager developer portal accepts user-supplied input without enforcing expected validation constraints or proper output encoding. This deficiency allows a malicious actor to inject script content that is executed within the context of a user's browser. By leveraging this cross-site scripting… | |
| Analizada | Media (6.1) | 0.24% | — | Wso2 API Manager | 16/4/2026 | 17/6/2026 | The authentication endpoint fails to adequately validate user-supplied input before reflecting it back in the response. This allows an attacker to inject malicious script payloads into the input parameters, which are then executed by the victim's browser. Successful exploitation can enable an attacker to redirect the… | |
| Pendiente de análisis | Alta (7.3) | 0.12% | — | Dell Storage Manager Replay Manager FOR Microsoft ServersAI | 16/4/2026 | 17/6/2026 | Dell Storage Manager - Replay Manager for Microsoft Servers, version(s) 8.0, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Crítica (9.1) | 0.38% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+1 | 16/4/2026 | 17/6/2026 | The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entities. This omission allows malicious actors to craft XML payloads that exploit the parser's behavior, leading to the inclusion of external resources. By leveraging this… |