Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
11.996 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.24% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 18/11/2025 | 17/6/2026 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components may permit… | |
| Aplazada | Media (5.3) | 0.29% | — | Pixel Manager FOR WoocommerceAI | 18/11/2025 | 17/6/2026 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.49.2 via the ajax_pmw_get_product_ids() function due to insufficient restrictions on which products can be included. This… | |
| Analizada | Alta (8.8) | 0.23% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 18/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective… | |
| Aplazada | Media (6.5) | 0.20% | — | ACF Flexible Layouts ManagerAI | 18/11/2025 | 17/6/2026 | The ACF Flexible Layouts Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'acf_flm_update_template_with_pasted_layout' function in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to update custom… | |
| Aplazada | Alta (8.8) | 0.42% | — | Digi On-prem ManagerAI | 17/11/2025 | 7/10/2026 | Se ha descubierto una vulnerabilidad de inyección en la característica de la API en Digi On-Prem Manager, permitiendo a un atacante con tokens de la API válidos inyectar SQL mediante entrada especialmente diseñada. La API no está habilitada por defecto, y se requiere un token de la API válido para realizar el ataque. | |
| Aplazada | Media (6.5) | 0.28% | — | Wedevs WP Project ManagerAI | 15/11/2025 | 7/10/2026 | La Gestión de Proyectos, Colaboración en Equipo, Tablero Kanban, Diagramas de Gantt, Gestor de Tareas y Más - el plugin WP Project Manager para WordPress es vulnerable a inyección SQL basada en tiempo a través del parámetro 'completed_at_operator' en todas las versiones hasta la 2.6.26, inclusive, debido a un escape… | |
| Aplazada | Media (6.5) | 0.15% | — | Oplugins Booking ManagerAI | 13/11/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en wpdevelop Booking Manager booking-manager permite XSS Almacenado. Este problema afecta a Booking Manager: desde n/a hasta menor o igual que 2.1.17. | |
| Modificada | Media (6.5) | 0.11% | — | Hasthemes WP Plugin Manager | 13/11/2025 | 7/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en HasThemes WP Plugin Manager wp-plugin-manager permite la falsificación de petición en sitios cruzados. Este problema afecta a WP Plugin Manager: desde n/a hasta menor o igual que 1.4.7. | |
| Aplazada | Media (4.3) | 0.19% | — | Nmedia Frontend File ManagerAI | 13/11/2025 | 7/10/2026 | Vulnerabilidad de autorización faltante en N-Media Frontend File Manager nmedia-user-file-uploader permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Frontend File Manager: desde n/a hasta menor o igual que 23.2. | |
| Analizada | Media (6.5) | 0.24% | — | IBM Qradar Security Information AND Event Manager | 12/11/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be read by an authenticated user. | |
| Aplazada | Media (5.2) | 0.10% | — | Lenovo Dock ManagerAI | 12/11/2025 | 17/6/2026 | An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during installation, could allow an authenticated local user to redirect log files with elevated privileges. | |
| Aplazada | Alta (7.7) | 0.21% | — | Lenovo PC ManagerAILenovo APP StoreAILenovo BrowserAILenovo Legion ZoneAI | 12/11/2025 | 17/6/2026 | A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code. | |
| Analizada | Media (6.7) | 0.35% | — | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 11/11/2025 | 17/6/2026 | Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.1) | 0.24% | — | Ivanti Endpoint Manager | 11/11/2025 | 17/6/2026 | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk | |
| Aplazada | Media (6.5) | 0.42% | — | Zoho Manageengine OpmanagerAI | 11/11/2025 | 17/6/2026 | Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap processor. | |
| Aplazada | Alta (8.4) | 0.32% | — | Verve Asset ManagerAI | 11/11/2025 | 17/6/2026 | A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and delete users via the API. | |
| Analizada | Media (5.1) | 0.17% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'. | |
| Aplazada | Alta (8.8) | 4.2% | 💥 PoC | Zohocorp Manageengine Applications ManagerAI | 11/11/2025 | 25/9/2026 | Las versiones 178100 y anteriores de Zohocorp ManageEngine Applications Manager son vulnerables a una vulnerabilidad de inyección de comandos autenticada debido a la configuración incorrecta en la función de acción “ejecutar programa”. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'. | |
| Aplazada | Media (4.4) | 0.22% | — | Fleet ManagerAI | 11/11/2025 | 7/10/2026 | El plugin Fleet Manager para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración de administrador en todas las versiones hasta la 2.5.1, inclusive, debido a la sanitización insuficiente de la entrada y al escape de la salida. Esto hace posible que atacantes autenticados, con permisos… | |
| Aplazada | Crítica (9.9) | 0.59% | — | SAP Solution ManagerAI | 11/11/2025 | 17/6/2026 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system. |