Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

11.996 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.24%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+518/11/202517/6/2026
A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components may permit…
AplazadaMedia (5.3)0.29%—Pixel Manager FOR WoocommerceAI18/11/202517/6/2026
The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.49.2 via the ajax_pmw_get_product_ids() function due to insufficient restrictions on which products can be included. This…
AnalizadaAlta (8.8)0.23%—Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+518/11/202517/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective…
AplazadaMedia (6.5)0.20%—ACF Flexible Layouts ManagerAI18/11/202517/6/2026
The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to update custom…
AplazadaAlta (8.8)0.42%—Digi On-prem ManagerAI17/11/20257/10/2026
Se ha descubierto una vulnerabilidad de inyección en la característica de la API en Digi On-Prem Manager, permitiendo a un atacante con tokens de la API válidos inyectar SQL mediante entrada especialmente diseñada. La API no está habilitada por defecto, y se requiere un token de la API válido para realizar el ataque.
AplazadaMedia (6.5)0.28%—Wedevs WP Project ManagerAI15/11/20257/10/2026
La Gestión de Proyectos, Colaboración en Equipo, Tablero Kanban, Diagramas de Gantt, Gestor de Tareas y Más - el plugin WP Project Manager para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'completed_at_operator' en todas las versiones hasta la 2.6.26, inclusive, debido a un escape…
AplazadaMedia (6.5)0.15%—Oplugins Booking ManagerAI13/11/20257/10/2026
Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en wpdevelop Booking Manager booking-manager permite XSS Almacenado. Este problema afecta a Booking Manager: desde n/a hasta menor o igual que 2.1.17.
ModificadaMedia (6.5)0.11%—Hasthemes WP Plugin Manager13/11/20257/10/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en HasThemes WP Plugin Manager wp-plugin-manager permite la falsificación de petición en sitios cruzados. Este problema afecta a WP Plugin Manager: desde n/a hasta menor o igual que 1.4.7.
AplazadaMedia (4.3)0.19%—Nmedia Frontend File ManagerAI13/11/20257/10/2026
Vulnerabilidad de autorización faltante en N-Media Frontend File Manager nmedia-user-file-uploader permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Frontend File Manager: desde n/a hasta menor o igual que 23.2.
AnalizadaMedia (6.5)0.24%—IBM Qradar Security Information AND Event Manager12/11/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user.
AplazadaMedia (5.2)0.10%—Lenovo Dock ManagerAI12/11/202517/6/2026
An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges.
AplazadaAlta (7.7)0.21%—Lenovo PC ManagerAILenovo APP StoreAILenovo BrowserAILenovo Legion ZoneAI12/11/202517/6/2026
A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code.
AnalizadaMedia (6.7)0.35%—Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250311/11/202517/6/2026
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.1)0.24%—Ivanti Endpoint Manager11/11/202517/6/2026
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
AplazadaMedia (6.5)0.42%—Zoho Manageengine OpmanagerAI11/11/202517/6/2026
Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor.
AplazadaAlta (8.4)0.32%—Verve Asset ManagerAI11/11/202517/6/2026
A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API.
AnalizadaMedia (5.1)0.17%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'.
AplazadaAlta (8.8)4.2%💥 PoCZohocorp Manageengine Applications ManagerAI11/11/202525/9/2026
Las versiones 178100 y anteriores de Zohocorp ManageEngine Applications Manager son vulnerables a una vulnerabilidad de inyección de comandos autenticada debido a la configuración incorrecta en la función de acción “ejecutar programa”.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'.
AnalizadaMedia (5.1)0.16%—Fairsketch Rise Ultimate Project Manager11/11/202517/6/2026
HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'.
AplazadaMedia (4.4)0.22%—Fleet ManagerAI11/11/20257/10/2026
El plugin Fleet Manager para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración de administrador en todas las versiones hasta la 2.5.1, inclusive, debido a la sanitización insuficiente de la entrada y al escape de la salida. Esto hace posible que atacantes autenticados, con permisos…
AplazadaCrítica (9.9)0.59%—SAP Solution ManagerAI11/11/202517/6/2026
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.