Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2838▲ 84 respecto a la semana anterior
Críticas / altas1318▼ 204 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

22.759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.29%—Cisco Integrated Management ControllerAI5/8/20266/8/2026
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could…
AplazadaBaja (2.1)0.35%—Imranrisal-dev Student-management-systemAI5/8/202612/8/2026
A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a manipulation of the argument…
AnalizadaAlta (8.8)0.49%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input.
AnalizadaCrítica (9.8)0.65%—IBM Qradar Security Information AND Event Manager5/8/202610/8/2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event processing pipeline ( q1labs_core.jar ). When at least one log source type is configured to use…
AplazadaCrítica (9.8)0.68%—Nasa Ammos Asynchronous Network Management SystemAI5/8/202626/8/2026
The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service's REST API directly to the host network interface (port 8089, e.g. ":8089/tcp") with cap_add: NET_ADMIN, NET_RAW, SYS_NICE, bypassing the CAM (Configuration and Access…
AplazadaAlta (7.2)0.50%—Wpdownloadmanager WP DownloadmanagerAI5/8/202626/8/2026
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no…
AplazadaAlta (8.2)0.51%—Toner-managementAI5/8/202626/8/2026
toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access control was enforced only in listing…
AplazadaCrítica (9.8)0.75%—Inventory-management-system-phpAI5/8/202626/8/2026
Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload such as email=' OR 1=1 LIMIT 1-- -.
AplazadaAlta (7.5)0.48%—Book-management-systemAI5/8/202626/8/2026
Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers, the entire student database can be…
Pendiente de análisisCrítica (9)0.58%—Redhat Advanced Cluster Management FOR KubernetesAI5/8/20268/9/2026
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a…
AplazadaCrítica (9.8)0.71%—Stock-inventory-management-systemAI5/8/202626/8/2026
The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly concatenating those session values into a SQL statement with no parameterization or escaping. The same script additionally contains hardcoded administrative credentials…
AplazadaMedia (6.5)0.45%—User Access ManagerAI5/8/202612/8/2026
The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and…
AplazadaMedia (5.5)0.41%—Shandong Hoteam PDM Product Data Management SystemAI5/8/202612/8/2026
A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection. Remote exploitation of the attack is…
AplazadaMedia (6.1)0.36%—Soliton Systems Mailzen Management PortalAI4/8/202631/8/2026
Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.
AplazadaMedia (5.5)0.50%—ResponsivefilemanagerAI4/8/202612/8/2026
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaAlta (7.3)0.19%—Geovision Gv-asmanagerAI4/8/20269/9/2026
A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary code. By placing a crafted dynamic-link library (DLL) file into the application search path prior to the legitimate library, the malicious code is loaded and executed…
AplazadaMedia (4.3)0.25%—Wired Impact Volunteer ManagementAI4/8/202626/8/2026
The Wired Impact Volunteer Management WordPress plugin before 2.8.2 does not have authorisation checks in one of its AJAX actions, and does not verify that the RSVP being removed belongs to the requesting user, allowing users with a role as low as Subscriber to remove arbitrary users' RSVPs from any volunteer…
AplazadaMedia (5.5)2.7%—Sangfor Operation AND Maintenance Security Management SystemAI3/8/202612/8/2026
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack…
AnalizadaAlta (7.8)0.17%—Dell Display AND Peripheral Manager3/8/20265/8/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.8)0.15%—Dell Display AND Peripheral Manager3/8/20265/8/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.
Pendiente de análisisCrítica (9.3)0.89%💥 PoCCheckpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI3/8/20265/8/2026
An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could…
AplazadaBaja (2.7)0.30%—TAG Category Taxonomy ManagerAI3/8/202626/8/2026
The Tag, Category, and Taxonomy Manager WordPress plugin before 3.51.0 does not verify that a user is authorized to access a referenced post before processing it and returning derived data, allowing users with contributor privileges to disclose data from private or draft posts they do not own.
AplazadaMedia (5.4)0.13%—Najeebmedia Frontend File ManagerAI2/8/202626/8/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,…
AplazadaMedia (5.4)0.23%—Event Booking ManagerAI2/8/202626/8/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and publication status of arbitrary posts and…
AplazadaMedia (5.4)0.23%—Event Booking ManagerAI2/8/202626/8/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to inject arbitrary JavaScript that executes…