Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
22.759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.37% | — | Sourcecodester Online Examination AND Learning Management SystemAI | 6/8/2026 | 12/8/2026 | A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely. | |
| Aplazada | Media (5.3) | 0.32% | — | Event Booking Manager FOR WoocommerceAI | 6/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price. This allows unauthenticated users to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpide File Manager AND Code EditorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpmanageninja Ninja TablesAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions. | |
| Aplazada | Alta (7.1) | 0.13% | — | Data443 Tracking Code ManagerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Events ManagerAI | 6/8/2026 | 22/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager events-manager allows Reflected XSS.This issue affects Events Manager: from n/a through 7.4.2. | |
| Analizada | Crítica (9.8) | 0.48% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/8/2026 | 10/8/2026 | Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full administrative account takeover. This… | |
| Aplazada | Media (5.5) | 0.43% | — | Sourcecodester Computer Repair Shop Management SystemAI | 6/8/2026 | 12/8/2026 | A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Baja (2.1) | 0.33% | — | Itsourcecode Hospital Management SystemAI | 6/8/2026 | 12/8/2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation of the argument editid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to… | |
| Analizada | Media (4.4) | 0.16% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 12/8/2026 | When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such… | |
| Analizada | Media (4.9) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 13/8/2026 | Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This allows for the persistence of these codes, enabling them to be potentially reused. If an attacker possesses both the authorization code and the associated client credentials (client ID and client… | |
| Analizada | Alta (7.5) | 0.41% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+4 | 6/8/2026 | 9/8/2026 | The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the… | |
| En análisis | Media (5.8) | 0.29% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+3 | 6/8/2026 | 9/8/2026 | The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data to be included within user claims, which are then used by downstream processes. Allowing unvalidated input into user claims can lead to various security risks. Malicious… | |
| Aplazada | Alta (7.5) | 0.43% | — | Events ManagerAI | 6/8/2026 | 26/8/2026 | The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads, allowing unauthenticated users to retrieve another user's in-progress upload when its temporary identifier is known. The identifier is high-entropy, is disclosed only to… | |
| Analizada | Crítica (10) | 0.59% | ⚠ Explotación activa💥 PoC | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 6/8/2026 | 25/9/2026 | The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result… | |
| Analizada | Crítica (9.4) | 0.67% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 6/8/2026 | 29/9/2026 | El script de autenticación condicional (autenticación adaptativa) no aplica correctamente la finalización de todos los pasos de autenticación requeridos cuando se configura un patrón específico de múltiples pasos que involucra ciertos autenticadores. Esto permite a un atacante eludir los desafíos de autenticación… | |
| Analizada | Baja (3.7) | 0.27% | — | Wso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking AM+1 | 6/8/2026 | 29/9/2026 | Cuando el inicio de sesión multiatributo está habilitado, la interfaz de inicio de sesión no logra enmascarar consistentemente la existencia de cuentas de usuario. Para usuarios válidos, el servidor resuelve y muestra su nombre de usuario canónico, mientras que para usuarios inexistentes, se hace eco de la entrada… | |
| Analizada | Media (5.4) | 0.14% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 6/8/2026 | 29/9/2026 | El procesador Ajax dentro de la consola Carbon no protege adecuadamente las operaciones que cambian el estado de ataques de falsificación de petición en sitios cruzados (CSRF). Específicamente, utiliza el método HTTP GET para estas operaciones, y aunque el atributo de cookie SameSite=Lax se emplea para la mitigación,… | |
| Aplazada | Alta (7.2) | 0.53% | — | Wpmanageninja FluentsmtpAI | 6/8/2026 | 12/8/2026 | The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to insufficient input sanitization and output… | |
| Aplazada | Alta (8.8) | 1.1% | — | File ManagerAI | 6/8/2026 | 12/8/2026 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server,… | |
| Aplazada | Media (5.5) | 0.41% | — | Imranrisal-dev Student-management-systemAI | 5/8/2026 | 12/8/2026 | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. Affected by this vulnerability is an unknown functionality of the file loginCheckTest.php of the component Login. The manipulation of the argument… | |
| Pendiente de análisis | Media (4.3) | 0.29% | — | Jenkins External Workspace Manager PluginAI | 5/8/2026 | 31/8/2026 | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with Overall/Read permission to read files in… | |
| Pendiente de análisis | Media (4.2) | 0.19% | — | Jenkins Scm-manager PluginAI | 5/8/2026 | 31/8/2026 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Pendiente de análisis | Media (4.2) | 0.11% | — | Jenkins Scm-manager PluginAI | 5/8/2026 | 31/8/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Pendiente de análisis | Media (6.5) | 0.13% | — | Cisco Catalyst Sd-wan ManagerAI | 5/8/2026 | 6/8/2026 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included… |