Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

12.001 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.48%—Carmelo Simple Leave Manager9/10/20258/10/2026
Se ha encontrado una falla en code-projects Simple Leave Manager 1.0. Esta vulnerabilidad afecta a código desconocido del archivo /user.php. Esta manipulación del argumento table causa inyección SQL. La explotación remota del ataque es posible. El exploit ha sido publicado y puede ser utilizado.
AplazadaCrítica (9.3)0.67%—Netsarang Xmanager EnterpriseAINetsarang XmanagerAINetsarang XshellAINetsarang XftpAI+19/10/202517/6/2026
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a specially crafted TXT record for a…
AnalizadaBaja (2.1)0.40%—Carmelo Student Result Manager9/10/20258/10/2026
Se determinó una vulnerabilidad en code-projects Student Result Manager 1.0. Esto afecta una función desconocida del archivo src/students/Database.java. Esta manipulación del argumento roll/name/gpa causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser…
AplazadaAlta (8)0.23%—Rancher ManagerAIRancher CLIAI2/10/202517/6/2026
A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.
AplazadaAlta (7.6)0.46%—Rancher ManagerAI2/10/202517/6/2026
A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.
AnalizadaMedia (5.1)0.21%—Creativeitem Ekushey Project Manager CRM2/10/202517/6/2026
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query…
AnalizadaMedia (5.1)0.21%—Creativeitem Ekushey Project Manager CRM2/10/202517/6/2026
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability could allow a remote attacker to send a specially crafted query to an…
AplazadaMedia (4.7)0.36%—Rancher ManagerAI2/10/202517/6/2026
A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. email addresses.
AnalizadaMedia (5.1)0.21%—Creativeitem Ekushey Project Manager CRM2/10/202530/9/2026
Vulnerabilidad de Cross Site Scripting Almacenado en Ekushey CRM v5.0 de Creativeitem, debido a la falta de validación adecuada de las entradas de usuario a través de la ruta '/ekushey/index.php/client/project_bug/create/xxx', afectando a los parámetros 'title' y 'description' vía POST. Esta vulnerabilidad podría…
AnalizadaMedia (6.1)0.25%—Joni1802 TS3 Manager1/10/202517/6/2026
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A reflected cross-site scripting vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability exists in the error handling mechanism of the login page, where malicious scripts embedded in server hostnames are executed in the…
AnalizadaAlta (7.5)0.48%—Joni1802 TS3 Manager1/10/202517/6/2026
TS3 Manager is modern web interface for maintaining Teamspeak3 servers. A Denial of Dervice vulnerability has been identified in versions 2.2.1 and earlier. The vulnerability permits an unauthenticated actor to crash the application through the submission of specially crafted Unicode input, requiring no prior…
AplazadaMedia (4.8)0.22%—Cisco Unified Communications ManagerAICisco Unified Communications Manager Session Management EditionAI1/10/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.…
AplazadaMedia (5.9)0.38%—Managefy File Manager Code Editor AND BackupAI1/10/20259/10/2026
El plugin File Manager, Code Editor y Backup by Managefy para WordPress es vulnerable a la Exposición de Información Sensible en todas las versiones hasta la 1.6.1, inclusive, a través de archivos de registro expuestos públicamente. Esto permite que atacantes no autenticados visualicen información como rutas completas…
AnalizadaAlta (7.8)0.10%—Dell Repository Manager29/9/20259/10/2026
Dell Repository Manager (DRM), versiones 3.4.7 y 3.4.8, contiene una vulnerabilidad de Manejo Inadecuado de Permisos o Privilegios Insuficientes. Un atacante con privilegios bajos y acceso local podría potencialmente explotar esta vulnerabilidad, lo que llevaría a una Elevación de privilegios.
ModificadaMedia (6.1)0.23%💥 PoCFairsketch Rise Ultimate Project Manager29/9/20255/7/2026
A cross-site scripting (XSS) vulnerability in FairSketch RISE Ultimate Project Manager & CRM 3.9.4 allows an administrator to store a JavaScript payload using the file explorer in the admin dashboard when creating new folders.
AplazadaMedia (4.3)0.14%—Shahjada Download ManagerAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request Forgery.This issue affects Download Manager: from n/a through <= 3.3.24.
AplazadaMedia (5.3)0.31%—Shahjada Download ManagerAI26/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.25.
AplazadaAlta (7.5)0.39%—Maciej BIS Permalink Manager LiteAI26/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Retrieve Embedded Sensitive Data.This issue affects Permalink Manager Lite: from n/a through <= 2.5.1.3.
AnalizadaAlta (7.2)0.54%—Wso2 Enterprise IntegratorWso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM26/9/202517/6/2026
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied filenames in the BPEL uploader SOAP service endpoint. A malicious actor with administrative privileges can upload arbitrary files to a user-controlled location on the server. By leveraging this…
AnalizadaMedia (5.3)0.25%—Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM26/9/202517/6/2026
A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this configuration, the system returns a distinct "User does not exist" error message to the login form, regardless of the validate_username setting. This behavior allows malicious actors to determine which…
AplazadaMedia (4.3)0.22%—Honzat Page Manager FOR ElementorAI26/9/20259/10/2026
Vulnerabilidad de exposición de información sensible del sistema a una esfera de control no autorizada en honzat Page Manager para Elementor permite la recuperación de datos sensibles incrustados. Este problema afecta a Page Manager para Elementor: desde n/a hasta 2.0.5.
AplazadaMedia (6.5)0.22%—Pickplugins JOB Board ManagerAI26/9/20259/10/2026
Vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web ('cross-site scripting') en PickPlugins Job Board Manager permite XSS basado en DOM. Este problema afecta a Job Board Manager: desde n/a hasta 2.1.61.
AplazadaMedia (4.4)0.20%—Zephyr Project ManagerAI26/9/202517/6/2026
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.3.202 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
AplazadaAlta (7.2)0.66%—Wpdownloadmanager Wp-downloadmanagerAI26/9/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on…
AnalizadaBaja (3.8)0.21%—Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM23/9/202517/6/2026
An authentication bypass vulnerability exists in multiple WSO2 products when FIDO authentication is enabled. When a user account is deleted, the system does not automatically remove associated FIDO registration data. If a new user account is later created using the same username, the system may associate the new…