Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

22.759 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Smart ManagerAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Smart Manager <= 8.90.0 versions.
AplazadaAlta (7.1)0.25%—Real Estate Manager PROAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions.
AplazadaAlta (8.8)0.70%—Mdjm Event ManagementAI23/7/202623/7/2026
The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()` functions, combined with the absence of…
AplazadaAlta (7.1)0.16%—Linux-gaming PortprotonqtAIGnome NetworkmanagerAI23/7/202623/7/2026
An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.
Pendiente de análisisAlta (8.4)0.11%—Bosch Configuration ManagerAI23/7/20261/10/2026
Revelación de información en Bosch Configuration Manager en la Versión 7.72.0106 permite a un atacante acceder a información sensible.
AplazadaAlta (8.8)0.20%—JoomlaAIRegularlabs Extension ManagerAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could…
AplazadaAlta (7.5)0.39%—Regularlabs Conditions ManagerAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
AplazadaMedia (4.8)0.24%—Regularlabs Conditions ManagerAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.
AplazadaAlta (8.8)0.20%—Regularlabs Conditions ManagerAI22/7/202627/7/2026
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
AnalizadaAlta (8.8)0.42%—Dell Powerprotect Data Manager22/7/202629/7/2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.2)0.50%—Dell Powerprotect Data Manager22/7/202629/7/2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.2)0.63%—Dell Powerprotect Data Manager22/7/202629/7/2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
AnalizadaMedia (4.4)0.15%—Dell Powerprotect Data Manager22/7/202629/7/2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaAlta (7.2)0.50%—Dell Powerprotect Data Manager22/7/202629/7/2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.2)0.50%—Dell Powerprotect Data Manager22/7/202629/7/2026
Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Pendiente de análisisCrítica (9.1)1.0%—Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI22/7/202624/7/2026
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation…
AnalizadaCrítica (9.3)78%⚠ Explotación activa💥 ExploitCheckpoint Multi-domain Security ManagementCheckpoint Quantum Security Management22/7/202610/8/2026
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security…
AplazadaMedia (6.5)0.36%💥 PoCUniverse Software Computer Marketing Trade AND Industry INC Online Registration AND Workflow Management SystemAI22/7/20265/8/2026
Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management System: through 12022026.
AplazadaAlta (7.5)0.45%—Events ManagerAI22/7/202622/7/2026
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI22/7/202622/7/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for…
AnalizadaAlta (7.7)0.35%—Oracle Human Resources Management System21/7/202627/7/2026
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle…
AnalizadaAlta (7.1)0.30%—Oracle Human Resources Management System21/7/202627/7/2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this…
AnalizadaMedia (6.5)0.35%—Oracle Human Resources Management System21/7/202627/7/2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this…
AnalizadaAlta (7.8)0.16%—Oracle Human Resources Management System21/7/202627/7/2026
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS…
AnalizadaAlta (7.7)0.35%—Oracle Human Resources Management System21/7/202627/7/2026
Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (Norway). While the…