Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
12.001 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 2.9% | 💥 Exploit | Avigilon Access Control Manager | 8/9/2025 | 17/6/2026 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL. | |
| Rechazada | Sin puntuar | — | 💥 PoC | Unisharp Laravel-filemanagerAI | 5/9/2025 | 5/9/2025 | Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager. | |
| Aplazada | Baja (3.8) | 0.25% | — | Pickplugins JOB Board ManagerAI | 5/9/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61. | |
| Aplazada | Alta (7.1) | 0.13% | — | Mark Odonnell Mstw League ManagerAI | 5/9/2025 | 5/10/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Mark O'Donnell MSTW League Manager mstw-league-manager permite XSS Almacenado. Este problema afecta a MSTW League Manager: desde n/a hasta menor o igual a 2.10. | |
| Aplazada | Media (6.5) | 0.22% | — | Ibnul H Custom Team ManagerAI | 5/9/2025 | 5/10/2026 | Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Ibnul H. Custom Team Manager custom-team-manager permite XSS Almacenado. Este problema afecta a Custom Team Manager: desde n/a hasta menor o igual a 2.4.2. | |
| Aplazada | Alta (7.6) | 0.37% | 💥 PoC | Wpexperts License Manager FOR WoocommerceAI | 5/9/2025 | 5/10/2026 | Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce permite Inyección SQL Ciega. Este problema afecta a License Manager for WooCommerce: desde n/a hasta menor o igual a 3.0.12. | |
| Aplazada | Alta (8.4) | 0.17% | — | Ratoc Systems Raid Monitoring ManagerAI | 5/9/2025 | 17/6/2026 | RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Crítica (9) | 53% | ⚠ Explotación activa💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0. | |
| Analizada | Alta (8.8) | 0.18% | — | Cisco Unified Communications Manager | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This… | |
| Analizada | Alta (8.8) | 0.32% | — | Cisco Evolved Programmable Network Manager | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An… | |
| Analizada | Media (4.8) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists… | |
| Analizada | Media (6.5) | 0.32% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 3/9/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system. | |
| Analizada | Media (6.1) | 0.25% | — | Cisco Unified Communications Manager IM AND Presence Service | 3/9/2025 | 1/10/2026 | Una vulnerabilidad en la interfaz de gestión basada en web de Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) podría permitir a un atacante remoto no autenticado realizar un ataque de cross-site scripting (XSS) contra un usuario de la interfaz. Esta vulnerabilidad existe porque la interfaz… | |
| Analizada | Alta (7.5) | 6.5% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4. | |
| Analizada | Crítica (9.8) | 20% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform… | |
| Analizada | Alta (8.8) | 1.6% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4. | |
| Analizada | Alta (8.8) | 0.29% | — | Upkeeper Manager | 3/9/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.0.0 before 5.2.12. | |
| Aplazada | Alta (8.2) | 0.52% | — | Rancher ManagerAI | 2/9/2025 | 17/6/2026 | A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessively large payloads, which are fully loaded into memory during processing,… | |
| Aplazada | Alta (7.1) | 0.17% | — | Dmitry V Barcode Scanner With Inventory AND Order ManagerAI | 31/8/2025 | 26/9/2026 | Vulnerabilidad de falta de autorización en UkrSolution Barcode Scanner with Inventory & Order Manager. Este problema afecta a Barcode Scanner with Inventory & Order Manager: desde n/a hasta 1.5.3. | |
| Aplazada | Alta (8.8) | 0.50% | — | Netsupport ManagerAI | 30/8/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory. | |
| Aplazada | Crítica (9.3) | 0.66% | — | Netsupport ManagerAI | 30/8/2025 | 17/6/2026 | A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code. | |
| Aplazada | Alta (7.6) | 0.26% | — | Honzat Page Manager FOR ElementorAI | 28/8/2025 | 17/6/2026 | Missing Authorization vulnerability in honzat Page Manager for Elementor page-manager-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Manager for Elementor: from n/a through <= 2.0.5. | |
| Aplazada | Crítica (9.8) | 0.41% | — | Manfcarlo WP Funnel ManagerAI | 28/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection.This issue affects WP Funnel Manager: from n/a through <= 1.4.0. | |
| Aplazada | Alta (7.1) | 0.22% | — | Dylan James Zephyr Project ManagerAI | 28/8/2025 | 25/9/2026 | Vulnerabilidad de autorización faltante en Dylan James Zephyr Project Manager permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Zephyr Project Manager: desde n/a hasta 3.3.201. | |
| Aplazada | Media (4.9) | 0.50% | 💥 PoC | Managefy File Manager Code Editor AND BackupAI | 28/8/2025 | 17/6/2026 | El complemento File Manager, Code Editor, and Backup by Managefy para WordPress es vulnerable a la Path Traversal en todas las versiones hasta la 1.4.8 incluida, mediante la función ajax_downloadfile(). Esto permite a atacantes autenticados, con acceso de suscriptor o superior, realizar acciones en archivos fuera del… |