Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
–

22.759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.29%—Ekushey Project Manager CRMAI27/7/202628/7/2026
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store…
AplazadaAlta (7.1)0.61%—Ekushey Project Manager CRMAI27/7/202628/7/2026
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting…
AplazadaAlta (7.1)0.25%—Product Feed ManagerAI27/7/202627/7/2026
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
AplazadaAlta (7.3)0.30%—Thrive Product ManagerAI27/7/202627/7/2026
Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions.
AplazadaAlta (7.5)0.37%—Booking AND Rental ManagerAI27/7/202627/7/2026
Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions.
AnalizadaAlta (8)0.26%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+127/7/202611/8/2026
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their…
AnalizadaAlta (8)0.26%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise.
AnalizadaAlta (8.4)1.7%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially…
AnalizadaAlta (8.4)1.7%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,…
AnalizadaAlta (8.4)1.7%—Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster27/7/202611/8/2026
An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially…
AplazadaBaja (1.8)0.20%💥 PoCZTE File ManagerAI27/7/202628/7/2026
The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level…
AplazadaAlta (7.5)0.39%—Download ManagerAI27/7/202627/7/2026
The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected…
AplazadaMedia (4.8)0.24%—Smart ManagerAI27/7/202627/7/2026
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid.
Pendiente de análisisAlta (8.5)0.57%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI24/7/202629/9/2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds…
AplazadaCrítica (9.3)0.65%—Sunnet Corporate Training Management SystemAI24/7/202628/7/2026
An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a…
AplazadaMedia (6.4)0.34%—Wpmanageninja Fluent SupportAI24/7/202624/7/2026
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AplazadaCrítica (9.1)0.41%—Project Management BUG AND Issue Tracking PluginAI24/7/202624/7/2026
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin…
AnalizadaAlta (8.8)0.96%—Microsoft Surface Management Services24/7/20266/8/2026
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
AnalizadaAlta (7.2)0.70%—Microsoft Azure API Management24/7/202617/8/2026
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Pendiente de análisisCrítica (10)4.7%—Zohocorp Manageengine Adaudit PlusAI23/7/202624/7/2026
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
AplazadaMedia (5.9)0.24%—Shop Manager TabsAI23/7/202623/7/2026
Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
AplazadaMedia (6.5)0.22%—Legoeso PDF ManagerAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions.
AplazadaMedia (5.3)0.33%—Wpmanageninja Ninja TablesAI23/7/202623/7/2026
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
AplazadaMedia (6.5)0.22%—Wpmanageninja Fluent SupportAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions.
AplazadaAlta (7.1)0.25%—Form Vibes Database Manager FOR FormsAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions.