Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service,… | |
| Pendiente de análisis | Alta (7.8) | 0.10% | — | Nvidia Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering,… | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Nvidia Vgpu Virtual GPU ManagerAI | 30/9/2026 | 1/10/2026 | NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 2/10/2026 | A vulnerability was identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. The affected element is the function mysqli_query of the file User/cancel.php of the component Order Cancellation. The manipulation of the argument ID leads to sql injection. The attack may be… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was determined in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Impacted is the function mysqli_query of the file User/ord.php of the component Order Placement. Executing a manipulation of the argument id/name can lead to sql injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.41% | — | Adithyayelloju Restaurant Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This issue affects the function mysqli_query of the file admin/delete1.php of the component Unauthenticated Action Script. Performing a manipulation of the argument ID results in sql injection. The… | |
| Aplazada | Media (6.5) | 0.13% | — | Yith Woocommerce TAB ManagerAI | 30/9/2026 | 30/9/2026 | Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions. | |
| Aplazada | Alta (7.1) | 0.15% | — | Premmerce Permalink ManagerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Premmerce Permalink Manager for WooCommerce <= 2.3.13 versions. | |
| Aplazada | Media (6.5) | 0.28% | — | MCP Content Manager LiteAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions. | |
| Aplazada | Alta (8.8) | 0.14% | — | Blacklist ManagerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | |
| Aplazada | Alta (7.6) | 0.28% | — | Admin Notices ManagerAI | 30/9/2026 | 30/9/2026 | Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. | |
| Aplazada | Media (6.5) | 0.16% | — | Pixelmanager Pixel ManagerAI | 30/9/2026 | 30/9/2026 | Contributor Cross Site Scripting (XSS) in Pixel Manager for WooCommerce <= 1.69.0 versions. | |
| Analizada | Crítica (9.8) | 1.8% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan Manager | 30/9/2026 | 2/10/2026 | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request… | |
| Aplazada | Media (6.4) | 0.19% | — | Real Estate ManagerAI | 30/9/2026 | 30/9/2026 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Baja (3.4) | 0.18% | — | Safe Redirect ManagerAI | 30/9/2026 | 30/9/2026 | The Safe Redirect Manager WordPress plugin before 2.3.0 does not properly validate the redirect destination when a wildcard redirect rule to an absolute URL is configured, allowing unauthenticated attackers to redirect visitors to an arbitrary external website via a crafted request path. | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester CAR Driving School Management SystemAI | 30/9/2026 | 2/10/2026 | A security flaw has been discovered in SourceCodester Car Driving School Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_enrollment. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Baja (2) | 0.21% | — | Sourcecodester Online Leave Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in SourceCodester Online Leave Management System 1.0. This issue affects some unknown processing of the file /admin/?page=reports. The manipulation of the argument date_start/date_end leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available… | |
| Aplazada | Media (5.5) | 0.27% | — | Sourcecodester Online Reviewer Management SystemAI | 30/9/2026 | 2/10/2026 | A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/examproper/exam-delete.php. The manipulation of the argument test_id results in sql injection. The attack can be launched remotely. The… | |
| Aplazada | Alta (7.2) | 0.25% | — | Frontend Post Submission Manager LiteAI | 30/9/2026 | 30/9/2026 | The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/examproper/btn_functions.php. The manipulation of the argument access_code leads to sql injection. The attack can be initiated remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.26% | — | Sourcecodester Online Reviewer Management SystemAI | 30/9/2026 | 30/9/2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/examproper/questions-view.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack… |