Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

11.968 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.7)1.1%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.
Pendiente de análisisAlta (8.8)3.7%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.
Pendiente de análisisAlta (8.8)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Application Manager PluginAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.
Pendiente de análisisCrítica (9.9)2.9%—Zoho Manageengine Opmanager MSPAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.
Pendiente de análisisAlta (7.1)0.60%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.
Pendiente de análisisAlta (7.1)0.60%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.
Pendiente de análisisAlta (8.1)0.85%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Privilege Escalation vulnerability that allowed an authenticated low-privilege user to gain Administrator privileges through Report Profile import.
Pendiente de análisisAlta (7.5)1.1%—Zohocorp Manageengine OpmanagerAIZohocorp Network Configuration ManagerAI23/9/202623/9/2026
ZohoCorp ManageEngine OpManager and Network Configuration Manager versions before 12.8.671 were vulnerable to an unauthorized Path Traversal vulnerability.
Pendiente de análisisAlta (8.8)0.97%—Zoho Manageengine OpmanagerAIZoho Manageengine Firewall AnalyzerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL Injection vulnerability in Rule Management Search Reports.
Pendiente de análisisAlta (7.6)1.5%—Zohocorp Manageengine OpmanagerAIZohocorp Netflow AnalyzerAIZohocorp Network Configuration ManagerAI23/9/202624/9/2026
ZohoCorp ManageEngine OpManager, NetFlow Analyzer, and Network Configuration Manager versions 12.8.667 and below were vulnerable to a Server-Side Template Injection vulnerability in Configlet processing, which could lead to Remote Code Execution.
AplazadaBaja (2.7)0.18%—Event Booking ManagerAI23/9/202623/9/2026
The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to events the requesting user is permitted to read, so users with contributor-level access and above can retrieve other authors' private, draft and trashed events, together with event detail the standard…
AplazadaMedia (4.3)0.15%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not verify that a request to modify a user's Booking Manager WordPress plugin before 2.1.21-specific settings targets the requesting user's own account, allowing any authenticated user with subscriber-level access and above to create or overwrite the Booking…
AplazadaMedia (6.8)0.23%—Oplugins Booking ManagerAI23/9/202623/9/2026
The Booking Manager WordPress plugin before 2.1.21 does not sanitize and escape values taken from a fetched external iCalendar feed before using them in a SQL query, allowing authenticated users with Author-level access and above to perform SQL injection attacks by importing a feed they control.
En análisisAlta (7.4)0.13%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.
En análisisBaja (3.7)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.
En análisisAlta (7.4)0.20%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.
AnalizadaMedia (6.5)0.19%—IBM Financial Transaction Manager22/9/20266/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.
AnalizadaCrítica (9.9)0.53%—IBM Financial Transaction Manager22/9/20266/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
AnalizadaCrítica (9.8)0.51%—IBM Financial Transaction Manager22/9/20266/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
AnalizadaCrítica (9.8)0.48%—IBM Financial Transaction Manager22/9/20266/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
AnalizadaMedia (4.3)0.20%—IBM Financial Transaction Manager22/9/20266/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.
En análisisMedia (6.5)0.24%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.
En análisisAlta (8)0.17%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.
En análisisMedia (5.4)0.14%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vectors.
En análisisAlta (7.4)0.12%—IBM Financial Transaction ManagerAIRedhat OpenshiftAI22/9/202623/9/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.
Orbitaley — Vulnerabilidades