Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

22.765 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.35%—Flexerasoftware Flexnet Manager SuiteAI19/6/202622/6/2026
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administrator level.
Pendiente de análisisCrítica (9.4)1.3%—Rancher ManagerAI19/6/202624/6/2026
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to break out of an image, and execute e.g. malicious containers.
AnalizadaAlta (7.8)0.14%—Dell Server Hardware Manager19/6/202626/6/2026
Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
AnalizadaAlta (7.5)1.0%—Microsoft Cost Management18/6/202626/6/2026
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
AplazadaMedia (6.5)0.40%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAIVmware Spring BootAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`,…
AplazadaAlta (7.5)0.31%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redacts configuration…
AnalizadaMedia (5.9)0.27%—Sonatype Nexus Repository Manager17/6/202621/7/2026
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.
ModificadaAlta (8)0.38%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.
ModificadaMedia (5.7)0.30%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.
ModificadaAlta (8.1)0.34%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Unauthorized access.
AnalizadaMedia (6.3)0.37%—F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+317/6/202611/8/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction…
ModificadaCrítica (9.2)1.1%💥 PoCF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source17/6/202616/7/2026
NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a…
ModificadaCrítica (9.2)6.5%💥 PoCF5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+717/6/202614/9/2026
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the…
ModificadaMedia (4.8)0.15%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.
ModificadaMedia (6.5)0.37%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
ModificadaAlta (8)0.25%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.
ModificadaAlta (7.1)0.32%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
ModificadaAlta (8.8)0.53%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information…
ModificadaAlta (8.1)0.35%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.
ModificadaAlta (7.5)0.21%—Dell Powerflex Manager17/6/202625/6/2026
Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
AplazadaMedia (6.4)0.33%—Permalink Manager LiteAI17/6/202617/6/2026
The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaAlta (8.5)0.35%—Effress Woocommerce Frontend Manager UltimateAI17/6/202617/6/2026
Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.
AnalizadaMedia (6.5)0.12%—Dell Powerflex Manager17/6/20261/10/2026
Dell PowerFlex Manager, versiones anteriores a la 4.5.1.1, contienen una vulnerabilidad de validación de certificado incorrecta. Un atacante remoto no autenticado podría potencialmente explotar esta vulnerabilidad, lo que llevaría a un ataque man-in-the-middle en conjunto con envenenamiento de caché DNS.
AplazadaMedia (5.3)0.22%—Weblizar School ManagementAI17/6/20266/10/2026
Referencias directas a objetos inseguras no autenticadas (IDOR) en School Management versiones menor o igual a 93.1.0.
AplazadaCrítica (9.8)0.45%—Support Ticket Management SystemAI17/6/20266/10/2026
Escalada de privilegios no autenticada en el Sistema de gestión de tickets de soporte versiones menor o igual a 1.9.