Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
22.747 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.27% | — | Gedelumbung HospitalmanagementAI | 30/9/2026 | 30/9/2026 | A flaw has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. The affected element is the function kirim of the file application/modules/web/controllers/buku_tamu.php of the component Guest Book. This manipulation of the argument nama/email/pesan causes cross site scripting.… | |
| Aplazada | Baja (2) | 0.23% | — | Gedelumbung HospitalmanagementAI | 30/9/2026 | 2/10/2026 | A vulnerability was detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Impacted is the function sistem.php::simpan of the file application/modules/admin/controllers/sistem.php of the component Configuration Handler. The manipulation of the argument tipe/title/content_setting… | |
| Aplazada | Media (5.5) | 0.31% | — | Gedelumbung HospitalmanagementAI | 30/9/2026 | 30/9/2026 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This issue affects the function error_reporting of the file index.php of the component HTTP Response. The manipulation leads to information disclosure. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2) | 0.26% | — | Gedelumbung Hospital ManagementAI | 30/9/2026 | 30/9/2026 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects the function detail of the file application/modules/admin/controllers/laporan_data_pasien.php. Executing a manipulation of the argument id_param can lead to authorization bypass.… | |
| Aplazada | Baja (2) | 0.33% | — | Gedelumbung HospitalmanagementAI | 30/9/2026 | 2/10/2026 | A security flaw has been discovered in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This affects the function hapus of the file application/modules/admin/controllers/data_galeri.php of the component Endpoint. Performing a manipulation of the argument gbr results in path traversal. The… | |
| Aplazada | Baja (2.1) | 0.28% | — | Gedelumbung HospitalmanagementAISunhater KcfinderAI | 29/9/2026 | 30/9/2026 | A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the… | |
| Analizada | Media (5.9) | 0.14% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.4) | 0.15% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. | |
| Analizada | Alta (7.8) | 0.08% | — | Dell Policy Manager FOR Secure Connect Gateway | 29/9/2026 | 6/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Crítica (9.9) | 0.36% | — | 3DS Geovia Geospatial Data ManagerAI | 29/9/2026 | 30/9/2026 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow an attacker to execute arbitrary code on the server. | |
| Pendiente de análisis | Alta (7.1) | 0.23% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 30/9/2026 | Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their… | |
| Pendiente de análisis | Crítica (9.1) | 0.45% | — | Nginxproxymanager Nginx Proxy ManagerAI | 28/9/2026 | 29/9/2026 | Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session… | |
| Aplazada | Baja (2.1) | 0.27% | — | Eleveo Quality ManagementAI | 28/9/2026 | 29/9/2026 | A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.createAndSaveAudit of the file /qm/cz.zoom.scorecard.webui.Scorecard/QMUtilsService of the component GWT RPC Handler. Performing a manipulation results in information disclosure. The attack is possible… | |
| Aplazada | Baja (2.1) | 0.36% | — | Eleveo Quality ManagementAI | 28/9/2026 | 29/9/2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of the file /qm/cz.zoom.scorecard.webui.Scorecard/cz.zoom.scorecard.webui.Scorecard/QMBODownload. The manipulation results in information disclosure. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.34% | — | Eleveo Quality ManagementAI | 28/9/2026 | 1/10/2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown functionality of the file Scorecard.jsp of the component Questionnaire Audio Upload. The manipulation leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| En análisis | Media (5.3) | 0.26% | — | Ordasoft Vehicle ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-detail page (task=view) echoes the title request parameter directly into a double-quoted HTML attribute with no output encoding of any kind. A double-quote character in the parameter closes the… | |
| En análisis | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Vehicle ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing… | |
| En análisis | Media (5.3) | 0.26% | — | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same… | |
| En análisis | Crítica (9.3) | 0.28% | 💥 PoC | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field… | |
| Aplazada | Media (5.6) | 0.11% | — | ABB Protection AND Control IED ManagerAI | 28/9/2026 | 28/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14. | |
| Aplazada | Alta (7.1) | 0.09% | — | ABB Protection AND Control IED ManagerAI | 28/9/2026 | 28/9/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14. | |
| Pendiente de análisis | Alta (8.8) | 0.88% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 7.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | |
| Pendiente de análisis | Alta (8.8) | 4.7% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. |