Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
22.759 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.29% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store… | |
| Aplazada | Alta (7.1) | 0.61% | — | Ekushey Project Manager CRMAI | 27/7/2026 | 28/7/2026 | Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field uniqueness enforcement to create conflicting… | |
| Aplazada | Alta (7.1) | 0.25% | — | Product Feed ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions. | |
| Aplazada | Alta (7.3) | 0.30% | — | Thrive Product ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Broken Access Control in Thrive Product Manager <= 10.9.2 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Booking AND Rental ManagerAI | 27/7/2026 | 27/7/2026 | Unauthenticated Other Vulnerability Type in Booking and Rental Manager <= 2.7.2 versions. | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Multi-tenant Loadmaster+1 | 27/7/2026 | 11/8/2026 | A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their… | |
| Analizada | Alta (8) | 0.26% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An Incorrect Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with low privileges to escalate privileges to root on the affected appliance, potentially resulting in full system compromise. | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the backup restore functionality, potentially… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the Geo Location management interface,… | |
| Analizada | Alta (8.4) | 1.7% | — | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 27/7/2026 | 11/8/2026 | An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF allows an authenticated attacker with high privileges to execute arbitrary operating system commands on the affected appliance via the management interface, potentially… | |
| Aplazada | Baja (1.8) | 0.20% | 💥 PoC | ZTE File ManagerAI | 27/7/2026 | 28/7/2026 | The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level… | |
| Aplazada | Alta (7.5) | 0.39% | — | Download ManagerAI | 27/7/2026 | 27/7/2026 | The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected… | |
| Aplazada | Media (4.8) | 0.24% | — | Smart ManagerAI | 27/7/2026 | 27/7/2026 | The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML attribute in its management grid, allowing users with the Contributor role or above to inject JavaScript that executes in the browser session of an administrator who views the grid. | |
| Pendiente de análisis | Alta (8.5) | 0.57% | — | Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI | 24/7/2026 | 29/9/2026 | A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Sunnet Corporate Training Management SystemAI | 24/7/2026 | 28/7/2026 | An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a… | |
| Aplazada | Media (6.4) | 0.34% | — | Wpmanageninja Fluent SupportAI | 24/7/2026 | 24/7/2026 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Crítica (9.1) | 0.41% | — | Project Management BUG AND Issue Tracking PluginAI | 24/7/2026 | 24/7/2026 | The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin… | |
| Analizada | Alta (8.8) | 0.96% | — | Microsoft Surface Management Services | 24/7/2026 | 6/8/2026 | Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. | |
| Analizada | Alta (7.2) | 0.70% | — | Microsoft Azure API Management | 24/7/2026 | 17/8/2026 | Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | |
| Pendiente de análisis | Crítica (10) | 4.7% | — | Zohocorp Manageengine Adaudit PlusAI | 23/7/2026 | 24/7/2026 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. | |
| Aplazada | Media (5.9) | 0.24% | — | Shop Manager TabsAI | 23/7/2026 | 23/7/2026 | Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Legoeso PDF ManagerAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in BSK PDF Manager <= 3.8 versions. | |
| Aplazada | Media (5.3) | 0.33% | — | Wpmanageninja Ninja TablesAI | 23/7/2026 | 23/7/2026 | Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wpmanageninja Fluent SupportAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Form Vibes Database Manager FOR FormsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Form Vibes – Database Manager for Forms <= 1.5.2 versions. |