Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3076▲ 446 respecto a la semana anterior
Críticas / altas1457▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
12.001 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.24% | — | Wso2 Identity ServerWso2 Identity Server AS KEY ManagerWso2 Open Banking IAM | 23/9/2025 | 17/6/2026 | A cross-tenant authentication vulnerability exists in multiple WSO2 products due to improper cryptographic design in Adaptive Authentication. A single cryptographic key is used across all tenants to sign authentication cookies, allowing a privileged user in one tenant to forge authentication cookies for users in other… | |
| Analizada | Media (4.3) | 0.21% | — | Wso2 API ManagerWso2 Identity Server | 23/9/2025 | 17/6/2026 | A content spoofing vulnerability exists in multiple WSO2 products due to improper error message handling. Under certain conditions, error messages are passed through URL parameters without validation, allowing malicious actors to inject arbitrary content into the UI. By exploiting this vulnerability, attackers can… | |
| Analizada | Alta (7.2) | 0.69% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Open Banking AMWso2 Traffic Manager | 23/9/2025 | 17/6/2026 | An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code,… | |
| Analizada | Media (4.8) | 0.19% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 23/9/2025 | 17/6/2026 | An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple WSO2 products due to improper validation of user-supplied input during API document upload in the Publisher portal. A user with publisher privileges can upload a crafted API document containing malicious JavaScript, which is later… | |
| Analizada | Media (6.5) | 0.32% | — | Wso2 API ManagerWso2 Micro Integrator | 23/9/2025 | 17/6/2026 | An information disclosure vulnerability exists in multiple WSO2 products due to improper implementation of the enrich mediator. Authenticated users may be able to view unintended business data from other mediation contexts because the internal state is not properly isolated or cleared between executions. This… | |
| Aplazada | Media (6.5) | 0.20% | — | Stonehenge Creations Events Manager OpenstreetmapsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stonehenge Creations Events Manager – OpenStreetMaps stonehenge-em-osm allows Stored XSS.This issue affects Events Manager – OpenStreetMaps: from n/a through <= 4.2.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Rameez Iqbal Real Estate ManagerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows DOM-Based XSS.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Modificada | Media (5.4) | 0.21% | — | Joomsky JS JOB Manager | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomSky JS Job Manager js-jobs allows Stored XSS.This issue affects JS Job Manager: from n/a through <= 2.0.2. | |
| Aplazada | Media (5.9) | 0.22% | — | Hamid Reza Yazdani E-namad Shamed Logo ManagerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hamid Reza Yazdani E-namad & Shamed Logo Manager e-namad-shamed-logo-manager allows Stored XSS.This issue affects E-namad & Shamed Logo Manager: from n/a through <= 2.2. | |
| Aplazada | Media (5.3) | 0.28% | — | Thimpress WP Events ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in ThimPress WP Events Manager wp-events-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Events Manager: from n/a through <= 2.2.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Meitar Subresource Integrity SRI ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Meitar Subresource Integrity (SRI) Manager wp-sri allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subresource Integrity (SRI) Manager: from n/a through <= 0.4.0. | |
| Aplazada | Media (5.3) | 0.32% | — | Nmedia Frontend File ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.3. | |
| Aplazada | Media (6.5) | 0.22% | — | Eleopard Behance Portfolio ManagerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5. | |
| Aplazada | Media (5.9) | 0.30% | — | Wp-experts.in Sales Count Manager FOR WoocommerceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-EXPERTS.IN Sales Count Manager for WooCommerce wc-sales-count-manager allows Stored XSS.This issue affects Sales Count Manager for WooCommerce: from n/a through <= 2.6. | |
| Analizada | Alta (8.8) | 0.83% | — | Creacast Creabox Manager | 22/9/2025 | 17/6/2026 | Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacker can inject arbitrary Lua code into the configuration, which is then executed on the server. This allows full system compromise, including reverse shell execution or… | |
| Aplazada | Media (5.3) | 0.29% | — | Wedevs WP Project ManagerAI | 22/9/2025 | 30/9/2026 | Vulnerabilidad de credenciales codificadas de forma rígida en weDevs WP Project Manager permite recuperar datos sensibles incrustados. Este problema afecta a WP Project Manager: desde n/d hasta 2.6.25. | |
| Analizada | Alta (8.8) | 0.49% | — | Creacast Creabox Manager | 22/9/2025 | 17/6/2026 | Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation. The system grants access when the username is creabox and the password begins with the string creacast, regardless of what follows. | |
| Aplazada | Media (5.3) | 0.30% | — | Dynamicweblab Wp-team-managerAI | 22/9/2025 | 5/10/2026 | Missing Authorization vulnerability in Dynamic Web Lab Team Manager wp-team-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Team Manager: from n/a through 2.6.8. | |
| Analizada | Alta (7.5) | 0.40% | — | Creacast Creabox Manager | 22/9/2025 | 17/6/2026 | Creacast Creabox Manager 4.4.4 exposes sensitive configuration data via a publicly accessible endpoint /get. When accessed, this endpoint returns internal configuration including the creacodec.lua file, which contains plaintext admin credentials. | |
| Aplazada | Alta (7.1) | 0.38% | — | Sitecore Experience ManagerAISitecore Experience PlatformAI | 21/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform… | |
| Aplazada | Media (4.3) | 0.16% | — | Internal Links ManagerAI | 20/9/2025 | 17/6/2026 | The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.1. This is due to missing or incorrect nonce validation on the link deletion functionality in the process_bulk_action() function. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.21% | — | IBM Copy Services Manager | 19/9/2025 | 17/6/2026 | IBM Copy Services Manager 6.3.13 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Media (6.1) | 0.22% | — | Download ManagerAI | 19/9/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘user_ids’ parameter in all versions up to, and including, 3.3.23 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (5.3) | 0.27% | — | Ericsson Catalog ManagerAIEricsson Order CareAI | 18/9/2025 | 17/6/2026 | Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue. | |
| Aplazada | Alta (8.4) | 0.74% | — | PodmanAICbis ManagerAI | 18/9/2025 | 17/6/2026 | The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without adequate validation,… |