Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2844▲ 206 respecto a la semana anterior
Críticas / altas1323▼ 110 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
11.996 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.45% | — | Cmsmadesimple File Manager | 10/11/2025 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Alta (7.3) | 0.14% | — | Dell Display AND Peripheral Manager | 10/11/2025 | 7/10/2026 | Dell Display and Peripheral Manager, versiones anteriores a la 2.1.2.12, contiene una vulnerabilidad de Ejecución con Privilegios Innecesarios en el Instalador. Un atacante con pocos privilegios y acceso local podría potencialmente explotar esta vulnerabilidad, lo que podría llevar a una Elevación de Privilegios. | |
| Aplazada | Media (6.5) | 0.22% | — | Ovatheme Events ManagerAI | 8/11/2025 | 7/10/2026 | El plugin Ovatheme Events Manager para WordPress es vulnerable a acceso no autorizado debido a una falta de verificación de capacidad en varias funciones en el archivo /class-ovaem-ajax.php en todas las versiones hasta la 1.8.6, inclusive. Esto hace posible que atacantes no autenticados eliminen archivos de tickets,… | |
| Aplazada | Media (5.3) | 0.24% | — | Download ManagerAI | 8/11/2025 | 7/10/2026 | El plugin Download Manager para WordPress es vulnerable a acceso no autorizado debido a una clave Cron codificada de forma rígida utilizada en las funciones deleteExpired() y clearTempDataCPCron() en todas las versiones hasta la 3.3.30, inclusive. Esto hace posible que atacantes no autenticados activen estos trabajos… | |
| Aplazada | Media (4.9) | 0.33% | — | TAG Category AND Taxonomy Manager AI Autotagger With OpenaiAI | 8/11/2025 | 7/10/2026 | El gestor de etiquetas, categorías y taxonomías - Autotagger de IA con plugin de OpenAI para WordPress es vulnerable a inyección SQL a través del parámetro 'post_types' en todas las versiones hasta la versión 3.40.0, inclusive, debido a un escape insuficiente en el parámetro proporcionado por el usuario y a la falta… | |
| Analizada | Media (6.5) | 0.16% | — | Rems Leads Manager Tool | 7/11/2025 | 17/6/2026 | The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints. | |
| Aplazada | Crítica (10) | 0.33% | — | Manager-io ManagerAI | 7/11/2025 | 17/6/2026 | Manager-io/Manager es un software de contabilidad. En las versiones de Manager Desktop y Server 25.11.1.3085 e inferiores, una vulnerabilidad crítica permite el acceso no autorizado a recursos de red internos. El fallo reside en el diseño fundamental del mecanismo de validación DNS. Una condición Time-of-Check… | |
| Analizada | Alta (8.1) | 0.40% | 💥 PoC | Alexusmai Laravel File Manager | 6/11/2025 | 17/6/2026 | alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Wpusermanager WP User ManagerAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12. | |
| Aplazada | Alta (7.1) | 0.23% | — | Magepeopleteam Booking AND Rental Manager FOR WoocommerceAI | 6/11/2025 | 7/10/2026 | Neutralización Incorrecta de la Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en magepeopleteam Booking and Rental Manager booking-and-rental-manager-for-woocommerce permite XSS Reflejado. Este problema afecta a Booking and Rental Manager: desde n/a hasta menor o igual que 2.5.3. | |
| Analizada | Media (6.1) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 5/11/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to improper output encoding. By tampering with specific parameters, a malicious actor can inject arbitrary JavaScript into the response, leading to reflected XSS. Successful exploitation could result in… | |
| Analizada | Media (6.1) | 0.21% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity Server | 5/11/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products due to a lack of output encoding. A malicious actor can inject arbitrary JavaScript payloads into the authentication endpoint, which are reflected back in the response, enabling browser-based attacks.… | |
| Analizada | Alta (7.2) | 0.47% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Micro Integrator+2 | 5/11/2025 | 17/6/2026 | An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the GraalJS and NashornJS Script Mediator engines. Authenticated users with elevated privileges can execute arbitrary code within the integration runtime environment. By default, access to these scripting… | |
| Modificada | Crítica (9.1) | 0.25% | — | Tonec Internet Download Manager | 5/11/2025 | 5/7/2026 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections. | |
| Analizada | Alta (7.2) | 0.60% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 5/11/2025 | 17/6/2026 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded content and destination in SOAP admin services. A malicious actor with administrative privileges can upload a specially crafted file to a user-controlled location within the deployment. Successful… | |
| Analizada | Crítica (9.1) | 0.46% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+4 | 5/11/2025 | 17/6/2026 | An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses user-supplied XML without applying sufficient restrictions, allowing resolution of external entities. A successful attack could enable a remote, unauthenticated attacker… | |
| Analizada | Alta (7.2) | 0.91% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+4 | 5/11/2025 | 17/6/2026 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code… | |
| Aplazada | Alta (7.5) | 2.5% | 💥 Exploit | File Manager FOR Google DriveAI | 5/11/2025 | 17/6/2026 | The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including… | |
| Aplazada | Alta (8.8) | 0.64% | — | EM Beer ManagerAI | 4/11/2025 | 17/6/2026 | The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all versions up to, and including, 3.2.3. This is due to missing file type validation in the EMBM_Admin_Untappd_Import_image() function and missing authorization checks on the wp_ajax_embm-untappd-import… | |
| Modificada | Media (6.5) | 0.38% | — | Fairsketch Rise Ultimate Project Manager | 3/11/2025 | 5/7/2026 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API. | |
| Analizada | Media (4.8) | 3.3% | 💥 PoC | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 31/10/2025 | 17/6/2026 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. | |
| Analizada | Media (5.4) | 0.21% | — | Dell Policy Manager FOR Secure Connect Gateway | 30/10/2025 | 7/10/2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versión(es) 5.20, 5.22, 5.24, 5.26, 5.28, contiene una vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web ('cross-site scripting'). Un atacante no autenticado con acceso remoto podría potencialmente explotar esta… | |
| Aplazada | Crítica (9.3) | 0.29% | — | Suse ManagerAI | 30/10/2025 | 17/6/2026 | A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run arbitrary javascript via a reflected XSS issue in the search fields.This issue affects Container suse/manager/5.0/x86_64/server:latest: from ? before 5.0.28-150600.3.36.8; SUSE Manager Server LTS 4.3:… | |
| Analizada | Media (6.9) | 0.27% | — | Vertikalsystems Hospital Manager Backend Services | 29/10/2025 | 8/10/2026 | Antes del 19 de septiembre de 2025, los Servicios de Backend del Gestor Hospitalario devolvían páginas de error ASP.NET detalladas para solicitudes WebResource.axd no válidas, revelando información sobre el framework y la versión de ASP.NET, rastros de pila, rutas internas y la configuración insegura 'customErrors… | |
| Analizada | Alta (8.7) | 0.42% | — | Vertikalsystems Hospital Manager Backend Services | 29/10/2025 | 8/10/2026 | Antes del 19 de septiembre de 2025, los Servicios de Backend del Gestor Hospitalario expusieron el endpoint de rastreo de ASP.NET /trace.axd sin autenticación, permitiendo a un atacante remoto obtener rastreos de solicitudes en vivo e información sensible como metadatos de solicitud, identificadores de sesión,… |