Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
22.759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.6) | 0.59% | — | Event Booking ManagerAI | 2/8/2026 | 26/8/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in the Event Booking Manager for WooCommerce… | |
| Aplazada | Alta (7.5) | 1.0% | — | User Access ManagerAI | 2/8/2026 | 12/8/2026 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.… | |
| Aplazada | Media (6.4) | 0.42% | — | Download ManagerAI | 1/8/2026 | 12/8/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.27% | — | Pixel TAG ManagerAI | 1/8/2026 | 26/8/2026 | The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to submit forged e-commerce conversion events to the site's configured server-side advertising conversion APIs using the site's stored credentials. | |
| Aplazada | Media (5.4) | 0.27% | — | Download ManagerAI | 1/8/2026 | 26/8/2026 | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated… | |
| Aplazada | Baja (3.8) | 0.26% | — | Wpmanageninja Fluent SupportAI | 1/8/2026 | 26/8/2026 | The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 31/8/2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Sourcecodester Modern Loan Management SystemAI | 31/7/2026 | 1/10/2026 | SourceCodester Modern Loan Management System 1.0 es vulnerable a inyección SQL en ajaxData.PHP a través de los parámetros district_id, division_id, region_id y ward_id. | |
| Aplazada | Alta (8.1) | 0.39% | — | Product Feed Manager FOR WoocommerceAI | 31/7/2026 | 26/8/2026 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks. | |
| Pendiente de análisis | Alta (7.8) | 0.36% | — | Yggdrasil Worker-package-managerAI | 31/7/2026 | 3/8/2026 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful… | |
| Analizada | Crítica (9.8) | 0.76% | — | IBM Hardware Management Console | 30/7/2026 | 10/8/2026 | IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | SourceCodester Tailor Management System 1.0 es vulnerable a inyección SQL en customeredit.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | Sistema de Gestión de Sastres SourceCodester 1.0 es vulnerable a inyección SQL en addmeasurement.PHP?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | El Sistema de Gestión de Membresías CodeAstro 1.0 es vulnerable a inyección SQL en renew.php a través del parámetro membershipType. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 es vulnerable a inyección SQL en el endpoint edit_type.PHP mediante el parámetro id. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Code RO Membership Management SystemAI | 30/7/2026 | 1/10/2026 | CodeAstro Membership Management System 1.0 es vulnerable a inyección SQL en /edit_member.PHP?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeatro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | El Sistema de Gestión de Membresías CodeAstro 1.0 es vulnerable a inyección SQL en report.php y revenue_report.php a través del parámetro fromDate. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 1/10/2026 | Sistema de Gestión de Membresías CodeAstro 1.0 es vulnerable a inyección SQL en /delete_members.PHP?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | CodeAstro Membership Management System 1.0 es vulnerable a inyección SQL en /memberProfile.PHP?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | El Sistema de Gestión de Membresías CodeAstro 1.0 es vulnerable a inyección SQL en /delete_membership.PHP?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Codeastro Membership Management SystemAI | 30/7/2026 | 5/10/2026 | El Sistema de Gestión de Membresías CodeAstro 1.0 es vulnerable a inyección SQL en /print_membership_card.PHP?id=1. | |
| Analizada | Media (6.1) | 0.27% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 29/9/2026 | IBM Engineering Requirements Management DOORS y DOORS Web Access 9.7.2.1 hasta 9.7.2.11, y 9.6.1.1 hasta 9.6.1.13 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un atacante no autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista… | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Engineering Requirements Management Doors WEB Access | 30/7/2026 | 1/10/2026 | IBM Engineering Requirements Management DOORS y DOORS Web Access 9.7.2.1 hasta 9.7.2.11, y 9.6.1.1 hasta 9.6.1.13 no limitan la longitud de una conexión, lo que podría permitir que se produzca un ataque de denegación de servicio HTTP Slowloris. Esto puede hacer que el servidor web deje de responder. | |
| Analizada | Crítica (9.3) | 0.38% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page. | |
| Analizada | Media (5.4) | 0.23% | — | IBM Websphere Application ServerIBM Tivoli System Automation Application Manager | 30/7/2026 | 18/8/2026 | IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console. |