Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
22.759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.44% | — | FTC Software IT Services FTC E-commerce Management PanelAI | 30/7/2026 | 30/7/2026 | Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2. | |
| Analizada | Media (6.8) | 0.46% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this… | |
| Analizada | Alta (7.6) | 0.32% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 12/8/2026 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL,… | |
| Analizada | Media (6.8) | 0.39% | — | Redhat Cost Management Metrics Operator | 30/7/2026 | 17/8/2026 | A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent… | |
| Aplazada | Alta (7.3) | 0.34% | — | Sourcecodester Advocate Office Management SystemAI | 29/7/2026 | 30/7/2026 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate… | |
| Aplazada | Alta (7.3) | 0.21% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | Sistema de Gestión Hospitalaria kishan0725 4.0 es vulnerable a inyección SQL en check_availability.php a través de los parámetros emailid y email. | |
| Aplazada | Alta (7.3) | 0.20% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 5/10/2026 | Sistema de Gestión Hospitalaria kishan0725 4.0 es vulnerable a inyección SQL en /doctor/edit-patient.php?editid=1. | |
| Aplazada | Alta (7.3) | 0.20% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | Sistema de Gestión Hospitalaria kishan0725 4.0 es vulnerable a inyección SQL en el endpoint view-medhistory.php a través del parámetro viewid. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | kishan0725 Hospital Management System 4.0 es vulnerable a inyección SQL en get_doctor.php a través de los parámetros doctor y specilizationid. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 5/10/2026 | Sistema de Gestión Hospitalaria kishan0725 4.0 es vulnerable a inyección SQL en /hms/doctor/view-patient.php?viewid=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Kishan0725 Hospital Management SystemAI | 29/7/2026 | 1/10/2026 | Sistema de Gestión Hospitalaria kishan0725 4.0 es vulnerable a inyección SQL en /betweendates-detailsreports.PHP. | |
| Analizada | Alta (7.4) | 0.13% | — | Devolutions Password Manager | 29/7/2026 | 21/8/2026 | Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate. | |
| Analizada | Media (5.3) | 35% | ⚠ Explotación activa | Cisco Secure Firewall Management Center | 29/7/2026 | 16/9/2026 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | |
| Aplazada | Media (6.4) | 0.33% | — | Wpclever WPC Badge ManagementAI | 29/7/2026 | 30/7/2026 | The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (4.3) | 0.40% | — | Eventbooking Event Booking Manager FOR WoocommerceAI | 29/7/2026 | 30/7/2026 | The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.3.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Analizada | Media (5.9) | 0.26% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |
| Analizada | Alta (8.6) | 0.25% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | |
| Aplazada | Alta (8.8) | 0.73% | — | Eazy Plugin ManagerAI | 28/7/2026 | 28/7/2026 | The Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.1. This is due to insufficient authorization on the `wp_ajax_pos_get_option` AJAX handler, which verifies only a nonce that is localized to… | |
| Analizada | Crítica (9.8) | 0.52% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie. | |
| Analizada | Alta (8.8) | 0.53% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains… | |
| Analizada | Crítica (9.8) | 0.33% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often,… | |
| Analizada | Alta (8.8) | 0.53% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases.… | |
| Analizada | Crítica (9.8) | 0.56% | — | Quest Kace Systems Management Appliance | 27/7/2026 | 3/8/2026 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious scripts that execute in the browser… | |
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. Attackers can craft and store malicious scripts… |