Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
11.968 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.39% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Baja (3.5) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL. | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write arbitrary files and conduct denial-of-service attacks. | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper encoding or escaping of output vulnerability in Auth API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to obtain non-sensitive information. | |
| Pendiente de análisis | Media (4.8) | 0.25% | — | Synology Diskstation ManagerAI | 18/9/2026 | 18/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files. | |
| Aplazada | Alta (7.5) | 0.46% | — | Ayecode Location ManagerAI | 18/9/2026 | 18/9/2026 | The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Aplazada | Media (6.5) | 0.34% | — | Wpinventory WP Inventory ManagerAI | 18/9/2026 | 18/9/2026 | The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query in… | |
| Aplazada | Media (6.5) | 0.41% | — | Download ManagerAI | 18/9/2026 | 18/9/2026 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any… | |
| Pendiente de análisis | Media (5.3) | 0.29% | — | Caddy Proxy ManagerAI | 17/9/2026 | 23/9/2026 | Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauthenticated remote actor to create an active account with the user role without… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Networkmanager-l2tpAI | 17/9/2026 | 23/9/2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu property values containing trailing non-numeric content after a valid integer. Attackers… | |
| Aplazada | Alta (8.2) | 0.28% | — | Joni1802 TS3 ManagerAI | 17/9/2026 | 30/9/2026 | TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and returns the resulting error.message through res.status(400).send(error.message) as… | |
| Pendiente de análisis | Alta (8.8) | 0.69% | 💥 PoC | Solarwinds Access Rights ManagerAI | 17/9/2026 | 18/9/2026 | SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpinventory WP Inventory ManagerAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Product Feed ManagerAI | 17/9/2026 | 17/9/2026 | Contributor SQL Injection in Product Feed Manager <= 7.12.0 versions. | |
| En análisis | Baja (3.5) | 0.24% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| En análisis | Alta (8.1) | 0.20% | — | Dell Smartfabric ManagerAI | 17/9/2026 | 18/9/2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Aplazada | Media (4.3) | 0.25% | — | Checkout Field ManagerAI | 17/9/2026 | 18/9/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. | |
| Aplazada | Media (4.3) | 0.25% | — | Checkout Field ManagerAI | 17/9/2026 | 18/9/2026 | The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitrary media attachments belonging to other users. | |
| Aplazada | Media (4.9) | 0.38% | — | Event Booking ManagerAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys. | |
| Aplazada | Baja (3.7) | 0.26% | — | Event Booking Manager FOR WoocommerceAI | 17/9/2026 | 18/9/2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.3.8 does not perform an ownership or authorization check before rendering booking confirmation details, allowing unauthenticated attackers to retrieve registered attendees' personal information (full name, email address, phone number, and custom… | |
| Aplazada | Media (5.3) | 0.34% | — | PatrowlmanagerAI | 16/9/2026 | 23/9/2026 | PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all users and their privilege flags including superuser and staff status by accessing the… | |
| Aplazada | Alta (7.1) | 0.38% | — | PatrowlmanagerAI | 16/9/2026 | 23/9/2026 | PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modify alerts belonging to other users. | |
| Pendiente de análisis | Alta (8.2) | 0.46% | — | Cisco Adaptive Security Device ManagerAICisco Secure FMC SoftwareAI | 16/9/2026 | 18/9/2026 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could… | |
| Pendiente de análisis | Media (5.4) | 0.63% | — | Adobe Experience ManagerAI | 16/9/2026 | 16/9/2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field.… | |
| Pendiente de análisis | Alta (8.5) | 0.32% | — | Dell Repository ManagerAI | 16/9/2026 | 17/9/2026 | Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |