Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

12.001 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)2.9%💥 ExploitAvigilon Access Control Manager8/9/202517/6/2026
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.
RechazadaSin puntuar—💥 PoCUnisharp Laravel-filemanagerAI5/9/20255/9/2025
Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager.
AplazadaBaja (3.8)0.25%—Pickplugins JOB Board ManagerAI5/9/202517/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
AplazadaAlta (7.1)0.13%—Mark Odonnell Mstw League ManagerAI5/9/20255/10/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Mark O'Donnell MSTW League Manager mstw-league-manager permite XSS Almacenado. Este problema afecta a MSTW League Manager: desde n/a hasta menor o igual a 2.10.
AplazadaMedia (6.5)0.22%—Ibnul H Custom Team ManagerAI5/9/20255/10/2026
Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en Ibnul H. Custom Team Manager custom-team-manager permite XSS Almacenado. Este problema afecta a Custom Team Manager: desde n/a hasta menor o igual a 2.4.2.
AplazadaAlta (7.6)0.37%💥 PoCWpexperts License Manager FOR WoocommerceAI5/9/20255/10/2026
Vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce permite Inyección SQL Ciega. Este problema afecta a License Manager for WooCommerce: desde n/a hasta menor o igual a 3.0.12.
AplazadaAlta (8.4)0.17%—Ratoc Systems Raid Monitoring ManagerAI5/9/202517/6/2026
RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
AnalizadaCrítica (9)53%⚠ Explotación activa💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
AnalizadaAlta (8.8)0.18%—Cisco Unified Communications Manager3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This…
AnalizadaAlta (8.8)0.32%—Cisco Evolved Programmable Network Manager3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An…
AnalizadaMedia (4.8)0.22%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system. This vulnerability exists…
AnalizadaMedia (6.5)0.32%—Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure3/9/202517/6/2026
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensitive information from an affected system.
AnalizadaMedia (6.1)0.25%—Cisco Unified Communications Manager IM AND Presence Service3/9/20251/10/2026
Una vulnerabilidad en la interfaz de gestión basada en web de Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) podría permitir a un atacante remoto no autenticado realizar un ataque de cross-site scripting (XSS) contra un usuario de la interfaz. Esta vulnerabilidad existe porque la interfaz…
AnalizadaAlta (7.5)6.5%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
AnalizadaCrítica (9.8)20%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform…
AnalizadaAlta (8.8)1.6%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
AnalizadaAlta (8.8)0.29%—Upkeeper Manager3/9/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Known Domain Credentials.This issue affects upKeeper Manager: from 5.0.0 before 5.2.12.
AplazadaAlta (8.2)0.52%—Rancher ManagerAI2/9/202517/6/2026
A vulnerability has been identified within Rancher Manager in which it did not enforce request body size limits on certain public (unauthenticated) and authenticated API endpoints. This allows a malicious user to exploit this by sending excessively large payloads, which are fully loaded into memory during processing,…
AplazadaAlta (7.1)0.17%—Dmitry V Barcode Scanner With Inventory AND Order ManagerAI31/8/202526/9/2026
Vulnerabilidad de falta de autorización en UkrSolution Barcode Scanner with Inventory & Order Manager. Este problema afecta a Barcode Scanner with Inventory & Order Manager: desde n/a hasta 1.5.3.
AplazadaAlta (8.8)0.50%—Netsupport ManagerAI30/8/202517/6/2026
A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory.
AplazadaCrítica (9.3)0.66%—Netsupport ManagerAI30/8/202517/6/2026
A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
AplazadaAlta (7.6)0.26%—Honzat Page Manager FOR ElementorAI28/8/202517/6/2026
Missing Authorization vulnerability in honzat Page Manager for Elementor page-manager-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page Manager for Elementor: from n/a through <= 2.0.5.
AplazadaCrítica (9.8)0.41%—Manfcarlo WP Funnel ManagerAI28/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager wp-funnel-manager allows Object Injection.This issue affects WP Funnel Manager: from n/a through <= 1.4.0.
AplazadaAlta (7.1)0.22%—Dylan James Zephyr Project ManagerAI28/8/202525/9/2026
Vulnerabilidad de autorización faltante en Dylan James Zephyr Project Manager permite explotar niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Zephyr Project Manager: desde n/a hasta 3.3.201.
AplazadaMedia (4.9)0.50%💥 PoCManagefy File Manager Code Editor AND BackupAI28/8/202517/6/2026
El complemento File Manager, Code Editor, and Backup by Managefy para WordPress es vulnerable a la Path Traversal en todas las versiones hasta la 1.4.8 incluida, mediante la función ajax_downloadfile(). Esto permite a atacantes autenticados, con acceso de suscriptor o superior, realizar acciones en archivos fuera del…