Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

22.747 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.25%—Pmticket Project-management-softwareAI23/9/202624/9/2026
A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates…
AplazadaMedia (5.5)0.28%—Neethuharii CafemanagementAI23/9/202624/9/2026
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and…
AplazadaAlta (7.2)0.40%—Reycob Shop ManagerAI23/9/202623/9/2026
Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.
AplazadaMedia (5.4)0.23%—Wpmanageninja Fluent SupportAI23/9/202623/9/2026
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.
AplazadaMedia (5.3)0.22%—Wpusermanager WP User ManagerAI23/9/202623/9/2026
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
Pendiente de análisisAlta (8.5)0.18%—Networkmanager-l2tpAIPppdAI23/9/202624/9/2026
NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local users with permission to create VPN connections to execute arbitrary code as root by injecting pppd options through a crafted VPN username. Attackers can embed a double-quote character or whitespace in…
AplazadaMedia (5.5)0.25%—Neethuharii CafemanagementAI23/9/202623/9/2026
A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public…
AplazadaMedia (5.5)0.28%—Neethuharii CafemanagementAI23/9/202623/9/2026
A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AnalizadaMedia (6.2)0.13%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions.
AnalizadaAlta (8.2)0.30%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression.
AnalizadaMedia (4.4)0.09%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management.
AnalizadaAlta (7.3)0.22%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool…
AnalizadaCrítica (9.3)0.19%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator…
AnalizadaMedia (5.4)0.15%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter` (`HostHeaderFilter.java:151`). An unauthenticated attacker can craft a request with a manipulated `Host` header to redirect authenticated operators to attacker-controlled sites, enabling credential…
AnalizadaAlta (8.8)0.25%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via Java native deserialization on the PayDir Business Rules Manager RMI SSL endpoint (BrmRMISSLServerSocketFactory.java:95, EP8). An adjacent-network attacker can deliver a crafted serialized payload to…
AnalizadaAlta (7.3)0.26%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive information and modify system configurations due to missing authentication for a critical function.
AnalizadaAlta (7.4)0.22%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to an XML external entity (XXE) injection flaw.
AnalizadaAlta (8.1)0.25%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and access sensitive information due to a hard-coded cryptographic key.
AnalizadaMedia (6.5)0.27%—IBM Financial Transaction Manager23/9/20267/10/2026
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to SQL injection.
AnalizadaAlta (7.5)0.26%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
AnalizadaMedia (6.3)0.08%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection…
AnalizadaAlta (7.4)0.25%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AnalizadaMedia (6.8)0.08%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection…
AnalizadaMedia (6.4)0.11%—Dell Policy Manager FOR Secure Connect Gateway23/9/202625/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and…
AnalizadaBaja (3.7)0.16%—Dell Policy Manager FOR Secure Connect Gateway23/9/202626/9/2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.