Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

22.764 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.39%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) almacenada que un atacante con privilegios bajos podría aprovechar para inyectar scripts maliciosos en campos de formulario vulnerables. Puede ejecutarse JavaScript malicioso en el navegador de la víctima…
AnalizadaAlta (8.6)1.0%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation…
AnalizadaMedia (5.4)0.39%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) almacenada que un atacante con privilegios bajos podría aprovechar para inyectar scripts maliciosos en campos de formulario vulnerables. Puede ejecutarse JavaScript malicioso en el navegador de la víctima…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaCrítica (9.6)0.90%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests, potentially gaining elevated access or…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaMedia (5.4)0.36%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager se ve afectado por una vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) basada en DOM. Un atacante podría explotar este problema manipulando el entorno DOM para ejecutar JavaScript malicioso en el contexto del navegador de la víctima. La explotación de este problema requiere…
AnalizadaAlta (8.6)0.89%—Adobe Experience Manager14/7/202628/8/2026
Adobe Experience Manager is affected by a Missing Authentication for Critical Function vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not require user…
AnalizadaAlta (8.8)0.78%💥 PoCMicrosoft Configuration Manager 2503Microsoft Configuration Manager 2509Microsoft Configuration Manager 260314/7/202630/7/2026
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
AnalizadaAlta (8.8)0.37%—Microsoft PC Manager14/7/202621/7/2026
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.37%—Microsoft PC Manager14/7/202617/7/2026
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Pendiente de análisisAlta (7.2)0.44%—Rockwellautomation ThinmanagerAI14/7/202614/7/2026
A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker could exploit this vulnerability to write arbitrary files to restricted system directories outside of the application's intended directory.
AnalizadaMedia (4.9)0.26%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if…
AnalizadaMedia (5.1)0.26%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This…
AnalizadaMedia (5.3)0.17%—Sonatype Nexus Repository Manager14/7/202622/9/2026
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0…
AnalizadaAlta (8.2)0.22%—Sonatype Nexus Repository Manager14/7/202622/9/2026
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
AnalizadaAlta (8.7)0.32%—Sonatype Nexus Repository Manager14/7/202622/9/2026
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user…
AplazadaBaja (2.1)0.33%—Codeastro Simple Online Leave Management SystemAI13/7/202613/7/2026
A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack is possible to be carried out remotely.…
AplazadaBaja (2.1)0.33%—Codeastro Simple Online Leave Management SystemAI13/7/202613/7/2026
A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has…
AplazadaMedia (5.3)0.29%—Magepeopleteam CAR Rental ManagerAI13/7/202613/7/2026
Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.
AplazadaMedia (5.4)0.29%—Wpexperts License Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.