Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.29%—Wpexperts License Manager FOR WoocommerceAI18/8/202620/8/2026
Customer SQL Injection in License Manager for WooCommerce <= 3.0.18 versions.
AplazadaMedia (5.4)0.29%—Wpexperts License Manager FOR WoocommerceAI13/7/202613/7/2026
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
AplazadaMedia (6.5)0.33%—Wpexperts License Manager FOR WoocommerceAI25/6/202629/6/2026
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
AplazadaCrítica (9.1)0.52%—Firassaidi Woocommerce License ManagerAI5/3/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in firassaidi WooCommerce License Manager fs-license-manager allows Upload a Web Shell to a Web Server.This issue affects WooCommerce License Manager: from n/a through <= 7.0.6.
AplazadaAlta (7.6)0.37%💥 PoCWpexperts License Manager FOR WoocommerceAI5/9/20255/10/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Blind SQL Injection.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.12.
AplazadaAlta (7.1)0.29%—Wpexperts License Manager FOR WoocommerceAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Reflected XSS.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.9.
AplazadaMedia (6.1)0.33%—Digital License ManagerAI25/3/202517/6/2026
The Digital License Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg() function without appropriate escaping on the URL in all versions up to, and including, 1.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AnalizadaMedia (6.1)0.27%—Reprisesoftware Reprise License Manager3/3/202517/6/2026
Reprise License Manager 14.2 is vulnerable to reflected cross-site scripting in /goform/activate_process via the akey parameter.
AplazadaMedia (6.1)0.27%—Quick License ManagerAI3/12/202417/6/2026
The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and including, 2.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
AplazadaCrítica (9.2)11%—Siemens Automation License ManagerAI10/9/202417/6/2026
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp.…
AnalizadaMedia (5.4)0.14%—Intel License Manager FOR Flexim14/8/202417/6/2026
Uncontrolled search path for some Intel(R) License Manager for FLEXlm product software before version 11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.39%—Wpexperts License Manager FOR Woocommerce21/6/202417/6/2026
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the showLicenseKey() and showAllLicenseKeys() functions in all versions up to, and including, 3.0.6. This makes it possible for authenticated attackers, with admin dashboard access…
AplazadaAlta (8.8)0.48%—Snowsoftware Snow License ManagerAI14/5/202417/6/2026
Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.
AplazadaAlta (7.1)0.38%—Firassaidi Woocommerce License ManagerAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firassaidi WooCommerce License Manager allows Reflected XSS.This issue affects WooCommerce License Manager: from n/a through 5.3.1.
ModificadaAlta (7.5)0.69%—Reprisesoftware Reprise License Manager3/2/202417/6/2026
Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted POST request.
ModificadaAlta (8.8)1.2%—Reprisesoftware Reprise License Manager3/2/202417/6/2026
Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack their account.
ModificadaAlta (7.2)0.70%—Wpexperts License Manager FOR Woocommerce30/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LicenseManager License Manager for WooCommerce license-manager-for-woocommerce allows SQL Injection.This issue affects License Manager for WooCommerce: from n/a through 2.2.10.
ModificadaMedia (4.8)0.33%—Snowsoftware Snow License Manager11/8/202317/6/2026
Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser
ModificadaAlta (7.2)0.56%—Snowsoftware Snow License Manager11/8/202317/6/2026
Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.
ModificadaMedia (4.3)0.38%—Snowsoftware Snow License Manager17/5/202317/6/2026
Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data.
ModificadaAlta (8.1)0.98%—Reprisesoftware Reprise License Manager20/1/20239/7/2026
Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.
ModificadaMedia (6.5)0.70%—Reprisesoftware Reprise License Manager20/1/20239/7/2026
CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.
ModificadaMedia (6.5)0.60%—Reprisesoftware Reprise License Manager20/1/20239/7/2026
An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers to trigger outbound requests to intranet servers, conduct port scans via the actserver parameter in License Activation function.
ModificadaCrítica (9.8)1.5%—Siemens Automation License Manager10/1/202317/6/2026
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files…
ModificadaAlta (7.5)0.97%—Siemens Automation License Manager10/1/202317/6/2026
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected components allow to rename license files with user chosen input without authentication. This could allow…
Orbitaley — Vulnerabilidades