Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
11.968 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 1.1% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature. | |
| Pendiente de análisis | Alta (8.8) | 3.7% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature. | |
| Pendiente de análisis | Alta (8.8) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability. | |
| Pendiente de análisis | Crítica (9.9) | 2.9% | — | Zoho Manageengine Opmanager MSPAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module. | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope. | |
| Pendiente de análisis | Alta (7.1) | 0.60% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope. | |
| Pendiente de análisis | Alta (8.1) | 0.85% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import. | |
| Pendiente de análisis | Alta (7.5) | 1.1% | — | Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 23/9/2026 | ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability. | |
| Pendiente de análisis | Alta (8.8) | 0.97% | — | Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports. | |
| Pendiente de análisis | Alta (7.6) | 1.5% | — | Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI | 23/9/2026 | 24/9/2026 | ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution. | |
| Aplazada | Baja (2.7) | 0.18% | — | Event Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard… | |
| Aplazada | Media (4.3) | 0.15% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking… | |
| Aplazada | Media (6.8) | 0.23% | — | Oplugins Booking ManagerAI | 23/9/2026 | 23/9/2026 | The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control. | |
| En análisis | Alta (7.4) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information. | |
| En análisis | Baja (3.7) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication. | |
| En análisis | Alta (7.4) | 0.20% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references. | |
| Analizada | Media (6.5) | 0.19% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling. | |
| Analizada | Crítica (9.9) | 0.53% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links. | |
| Analizada | Crítica (9.8) | 0.51% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data. | |
| Analizada | Crítica (9.8) | 0.48% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor. | |
| Analizada | Media (4.3) | 0.20% | — | IBM Financial Transaction Manager | 22/9/2026 | 6/10/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header. | |
| En análisis | Media (6.5) | 0.24% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization. | |
| En análisis | Alta (8) | 0.17% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key. | |
| En análisis | Media (5.4) | 0.14% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors. | |
| En análisis | Alta (7.4) | 0.12% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 22/9/2026 | 23/9/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures. |