Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

22.765 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)0.87%—Dell Wyse Management Suite25/6/202626/6/2026
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
AnalizadaAlta (7.8)0.09%—Dell Display AND Peripheral Manager25/6/202610/7/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
AnalizadaAlta (7.8)0.15%—Dell Display AND Peripheral Manager25/6/202610/7/2026
Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaAlta (7)0.10%—Dell Display AND Peripheral Manager25/6/202610/7/2026
Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
AnalizadaCrítica (9.8)0.39%—Dell Wyse Management Suite25/6/202626/6/2026
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
AnalizadaAlta (8.2)0.22%—Microfocus Access Manager24/6/202629/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.
AnalizadaMedia (6.3)0.30%—Microfocus Access Manager24/6/202629/6/2026
An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.
AplazadaAlta (8.8)0.83%—Jenkins External Workspace Manager PluginAI24/6/202625/6/2026
Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code…
AplazadaMedia (5.3)0.44%—Rentmy Real Time Rental ManagementAI24/6/202625/6/2026
The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read, create,…
AplazadaMedia (4.3)0.39%—Advance NAV Menu ManagerAI24/6/202625/6/2026
The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above,…
Pendiente de análisisCrítica (9)2.5%💥 PoCManageengine Adselfservice PlusAIManageengine Recoverymanager PlusAIManageengine M365 Manager PlusAIManageengine Adaudit PlusAI23/6/202624/6/2026
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
AplazadaAlta (7.5)0.41%—Najeebmedia Frontend File ManagerAI23/6/202623/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.
AplazadaMedia (5.4)0.23%—Najeebmedia Frontend File ManagerAI23/6/202623/6/2026
The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the frontend file-rename endpoint before storing it as post meta and rendering it back on the admin File Manager listing, leading to a Stored Cross-Site Scripting vulnerability exploitable by users with…
AnalizadaAlta (7.8)0.17%—Dell Wyse Management Suite22/6/202626/6/2026
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (4.4)0.15%—Dell Wyse Management Suite22/6/202626/6/2026
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
AnalizadaAlta (8.8)0.44%—Dell Wyse Management Suite22/6/202626/6/2026
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaAlta (8.8)0.44%—Dell Wyse Management Suite22/6/202626/6/2026
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (6.1)0.25%—IBM Engineering Workflow Management22/6/20261/10/2026
IBM Engineering Workflow Management 7.0.2 hasta 7.0.2 Interim Fix 035, 7.0.3 hasta 7.0.3 Interim Fix 017, y 7.1 hasta 7.1 Interim Fix 004 es vulnerable a la inyección de encabezados HTTP, causada por una validación incorrecta de la entrada por parte de los encabezados HOST. Esto podría permitir a un atacante realizar…
AnalizadaMedia (5.4)0.23%—IBM Engineering Workflow Management22/6/20266/10/2026
IBM Engineering Workflow Management 7.0.3 hasta 7.0.3 Interim Fix 020, y 7.1 hasta 7.1 Interim Fix 007 es vulnerable a cross-site scripting. Esta vulnerabilidad permite a un usuario autenticado incrustar código JavaScript arbitrario en la interfaz de usuario web, alterando así la funcionalidad prevista, lo que podría…
AplazadaAlta (7.1)0.16%—Aomei Dynamic Disk ManagerAI21/6/202622/6/2026
A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public…
AplazadaBaja (2.1)0.32%—Montodel House-rental-managementAI21/6/202622/6/2026
A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may…
AplazadaMedia (5.5)0.41%—Montodel House-rental-managementAI21/6/202623/6/2026
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now…
AnalizadaAlta (8.8)0.49%—Cmsjunkie Classifiedsmanager19/6/202619/8/2026
Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the…
AnalizadaAlta (8.8)0.43%—King-products Learning Management System King19/6/202619/8/2026
Joomla LMS King Professional 3.2.4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cp_id parameter. Attackers can send GET requests to index.php with the option=com_lmsking, view=lmsking, layout=learningpath, and…
Pendiente de análisisAlta (7.1)0.35%—Flexerasoftware Flexnet Manager SuiteAI19/6/202622/6/2026
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized access to attachment files due to insufficient access control.