Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3234▲ 671 respecto a la semana anterior
Críticas / altas1517▲ 124 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
22.765 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.15% | — | Devolutions Remote Desktop Manager | 16/6/2026 | 17/6/2026 | Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via a crafted web entry pointing to a provider lookalike domain. | |
| Modificada | Alta (8.8) | 0.44% | — | Devolutions Remote Desktop Manager | 16/6/2026 | 20/7/2026 | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a remote SSH host using stored elevation credentials via a crafted alternate username and user interaction with the Elevate Shell action. This… | |
| Aplazada | Alta (7.5) | 0.42% | — | Wpaffiliatemanager Affiliates ManagerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Sensitive Data Exposure in Affiliates Manager <= 2.9.50 versions. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Wpusermanager WP User ManagerAI | 15/6/2026 | 17/6/2026 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Managewp WorkerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in ManageWP Worker <= 4.9.31 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Event Tickets ManagerAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions. | |
| Pendiente de análisis | Media (6.5) | 0.23% | — | Nginx Proxy ManagerAI | 15/6/2026 | 17/6/2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET request. | |
| Analizada | Media (6.5) | 28% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan Manager | 15/6/2026 | 24/7/2026 | Una vulnerabilidad en la interfaz de usuario web de Cisco Catalyst SD-WAN Manager, anteriormente SD-WAN vManage, podría permitir a un atacante remoto autenticado crear o sobrescribir cualquier archivo en el sistema de archivos de un sistema afectado. Esta vulnerabilidad existe porque el software afectado no valida… | |
| Analizada | Alta (8.8) | 1.0% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client… | |
| Analizada | Crítica (9.8) | 1.5% | — | Fortra Core Privileged Access Manager Server | 15/6/2026 | 28/7/2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing. | |
| Aplazada | Alta (8.8) | 0.30% | — | 404 Redirection ManagerAI | 15/6/2026 | 17/6/2026 | The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate… | |
| Aplazada | Crítica (9.3) | 0.71% | — | Responsivefilemanager Responsive FilemanagerAI | 15/6/2026 | 17/6/2026 | Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0 | |
| Aplazada | Baja (2) | 0.21% | — | Codeastro Student Attendance Management SystemAI | 13/6/2026 | 23/7/2026 | Una vulnerabilidad fue detectada en CodeAstro Student Attendance Management System 1.0. Afectada es una función desconocida del archivo /attendance-PHP/Admin/createStudents.php. Realizar una manipulación del argumento admissionNumber resulta en inyección SQL. La explotación remota del ataque es posible. El exploit… | |
| Aplazada | Alta (7.4) | 0.26% | — | Avira Password ManagerAIMozilla FirefoxAI | 12/6/2026 | 23/7/2026 | Vulnerabilidad de revelación de información en Avira Password Manager cuando se usa con Mozilla Firefox puede permitir a un atacante remoto que opera un iframe de origen cruzado obtener credenciales autorrellenadas para la página web principal mediante una selección incorrecta del campo de autorrelleno. Este problema… | |
| Aplazada | Baja (2.1) | 0.25% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A weakness has been identified in CodeAstro Human Resource Management System 1.0. This vulnerability affects the function Invoice of the file \application\controllers\Payroll.php of the component Payroll Invoice Module. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is… | |
| Aplazada | Baja (2) | 0.20% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of the file /Projects/Add_Projects of the component Projects Management Page. The manipulation of the argument protitle results in cross site scripting. The attack may be launched remotely. The exploit… | |
| Aplazada | Baja (2) | 0.20% | — | Codeastro Human Resource Management SystemAI | 12/6/2026 | 17/6/2026 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown functionality of the file /dashboard/add_tod of the component Dashboard Interface. The manipulation of the argument todo_data leads to cross site scripting. The attack may be initiated remotely. The… | |
| Analizada | Media (4.4) | 0.42% | — | Metal3 Ip-address-manager | 12/6/2026 | 17/6/2026 | IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM controller's ClusterRole granted full CRUD permissions (create, delete, get, list, patch, update, watch) on core/v1 Secrets. The controller never accesses Secrets during normal operation. If the… | |
| Aplazada | Crítica (9.3) | 0.35% | — | IEI Integration Corp Irm-iei Remote ManagementAI | 12/6/2026 | 17/6/2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing unauthenticated remote attackers to exploit hard-coded credentials to gain administrative privileges on the database. | |
| Analizada | Alta (8.7) | 0.63% | — | Paloaltonetworks Idira Privileged Access Manager Vault | 12/6/2026 | 7/7/2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized… | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 | |
| Analizada | Alta (8.7) | 0.81% | — | Paloaltonetworks Idira Privileged Session Manager FOR SSH | 11/6/2026 | 23/6/2026 | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18 | |
| Analizada | Alta (8.7) | 0.72% | — | Paloaltonetworks Idira Privileged Session Manager | 11/6/2026 | 23/6/2026 | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18 | |
| Analizada | Alta (8.5) | 0.17% | — | Paloaltonetworks Idira Endpoint Privilege Manager | 11/6/2026 | 22/6/2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent… | |
| Analizada | Alta (8.4) | 0.51% | — | Paloaltonetworks Idira Secrets ManagerPaloaltonetworks Idira Secrets Manager Credential Providers | 11/6/2026 | 22/6/2026 | Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endpoints. A remote, authenticated attacker possessing standard node-level credentials could leverage these endpoints to potentially retrieve unauthorized secrets or cause a denial of service (DoS).… |