Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2732▼ 9 respecto a la semana anterior
Críticas / altas1276▼ 237 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

22.754 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)0.15%—Lenovo Accessories AND Display Manager FOR EnterpriseAI13/8/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
AplazadaMedia (5.4)0.18%—Basecamp UprightAIPrometheusAIPrometheus AlertmanagerAI13/8/20268/9/2026
basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as…
AplazadaAlta (7.2)0.54%—CAR Rental ManagerAI13/8/202614/8/2026
Editor PHP Object Injection in Car Rental Manager <= 1.3.9 versions.
AplazadaAlta (7.5)0.35%—Taxi Booking ManagerAI13/8/202614/8/2026
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Pendiente de análisisAlta (8.8)1.4%—Zohocorp Manageengine Password Manager PROAIZohocorp Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Pendiente de análisisAlta (8.8)3.1%—Zohocorp Manageengine Password Manager PROAIZohocorp Manageengine Pam360AI13/8/202631/8/2026
Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL injection.
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client12/8/20265/9/2026
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the insights-client pod or ServiceAccount…
Pendiente de análisisCrítica (9.9)0.81%—Redhat Advanced Cluster ManagementAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly privileged ServiceAccount (SA). This enables…
AnalizadaAlta (7.8)0.15%—Dell Display AND Peripheral Manager12/8/202617/8/2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
AnalizadaAlta (7.8)0.15%—Dell Display AND Peripheral Manager12/8/202617/8/2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
AnalizadaAlta (7.8)0.18%—Dell Display AND Peripheral Manager12/8/202617/8/2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
AnalizadaAlta (7.8)0.18%—Dell Display AND Peripheral Manager12/8/202617/8/2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
AnalizadaAlta (8.1)0.46%—Fortinet FortimanagerFortinet Fortimanager Cloud12/8/20268/9/2026
A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access…
AplazadaCrítica (9.8)0.50%💥 PoCEvents ManagerAI12/8/202626/8/2026
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID…
AplazadaAlta (8.1)0.39%—Events ManagerAI12/8/202626/8/2026
The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to other people.
AplazadaMedia (5.3)0.32%—User Access ManagerAI12/8/202626/8/2026
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Pendiente de análisisAlta (7.7)0.48%—Redhat Advanced Cluster ManagementAIRedhat Multicloud Operators ChannelAI12/8/202627/8/2026
A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets and ConfigMaps within any Channel…
Pendiente de análisisCrítica (9.9)0.70%—Argoproj ArgocdAIOpen Cluster Management Multicloud IntegrationsAI12/8/202627/8/2026
A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub cluster can exploit this to target arbitrary…
Pendiente de análisisCrítica (9.6)0.52%—Argoproj ArgocdAIRedhat Advanced Cluster ManagementAIRedhat Multicloud IntegrationsAI12/8/202627/8/2026
A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure…
ModificadaAlta (7.7)0.50%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every…
ModificadaMedia (6.8)0.69%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability…
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized…
En análisisMedia (5.4)0.16%—Cluster Management Toolkit FOR KubernetesAI11/8/202612/8/2026
Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result…
Pendiente de análisisMedia (5.6)0.12%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI11/8/202612/8/2026
Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may…
Pendiente de análisisAlta (8.2)0.32%—Intel Active Management TechnologyAIIntel Standard ManageabilityAI11/8/202612/8/2026
Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially…