Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▼ 7 respecto a la semana anterior
Críticas / altas1273▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
22.754 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.24% | — | Intel AMTAIIntel Standard ManageabilityAI | 11/8/2026 | 12/8/2026 | Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access… | |
| Pendiente de análisis | Crítica (9.8) | 3.3% | — | Manageengine DDI CentralAI | 11/8/2026 | 31/8/2026 | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. | |
| Pendiente de análisis | Alta (7) | 0.16% | — | AMD Power Design ManagerAI | 11/8/2026 | 29/9/2026 | Una vulnerabilidad de secuestro de DLL en AMD Power Design Manager podría permitir a un atacante local malicioso escalar privilegios durante el proceso de desinstalación, lo que podría resultar en ejecución de código arbitrario. | |
| Pendiente de análisis | Alta (8.1) | 1.5% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections. | |
| Pendiente de análisis | Alta (7.7) | 0.72% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. | |
| Pendiente de análisis | Alta (8.5) | 1.8% | — | Zohocorp Manageengine M365 Manager PlusAIZohocorp Manageengine M365 Security PlusAI | 11/8/2026 | 31/8/2026 | Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module. | |
| Aplazada | Crítica (9.3) | 0.64% | — | WIN MEN International Travel Agency Management SystemAI | 11/8/2026 | 26/8/2026 | Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Pendiente de análisis | Baja (3.7) | 0.19% | — | SAP Data Services Management ConsoleAI | 11/8/2026 | 26/8/2026 | SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks certain restrictive directives, which could enable an authenticated malicious user to leverage this weakness in combination with another vulnerability to inject and execute malicious scripts within… | |
| Aplazada | Media (4.3) | 0.27% | — | Library Management SystemAI | 10/8/2026 | 26/8/2026 | The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including user password hashes. | |
| Aplazada | Alta (7.5) | 0.42% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents… | |
| Aplazada | Alta (7.5) | 0.43% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | |
| Aplazada | Alta (8.8) | 0.42% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to… | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Task Management SystemAI | 10/8/2026 | 12/8/2026 | A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in cross site scripting. It is possible to launch the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 9/8/2026 | 12/8/2026 | A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 9/8/2026 | 12/8/2026 | A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.55% | — | Code-projects Task Management SystemAI | 9/8/2026 | 14/8/2026 | A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management SystemAI | 9/8/2026 | 12/8/2026 | A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Task Management SystemAI | 9/8/2026 | 12/8/2026 | A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and… | |
| Aplazada | Media (5.5) | 0.67% | — | Code-projects Task Management SystemAI | 9/8/2026 | 12/8/2026 | A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public… | |
| Analizada | Alta (8.7) | 0.48% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection.… | |
| Analizada | Alta (8.9) | 0.29% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 23/9/2026 | A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment. | |
| Analizada | Alta (8.7) | 0.25% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing… | |
| Analizada | Media (6.9) | 0.34% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding… | |
| Analizada | Media (5.3) | 0.23% | — | Sonatype Nexus Repository Manager | 7/8/2026 | 22/9/2026 | Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the… |