Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

23 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.58%—Userproplugin Media Manager30/1/202517/6/2026
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img() function in all versions up to, and including, 3.11.0. This makes it possible for unauthenticated attackers to update…
AnalizadaMedia (6.5)0.36%—Userproplugin Media Manager30/1/202517/6/2026
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the upm_upload_media() function in all versions up to, and including, 3.12.0. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)18%—Accesspressthemes AccessbuddyAccesspressthemes Accesspress Anonymous PostAccesspressthemes Accesspress BasicAccesspressthemes Accesspress Custom CSS+8921/2/202217/6/2026
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199408.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 199406.
ModificadaMedia (6.5)1.2%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-ForceID: 194597.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194596.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194595.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194594.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 194593.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194449.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 193737.
ModificadaMedia (5.4)0.50%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192470.
ModificadaMedia (6.5)0.80%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products could allow an authenticated user to obtain sensitive information due to lack of security restrictions. IBM X-Force ID: 188126.
ModificadaAlta (8.8)2.6%—IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle ManagementIBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Lifecycle Optimization - Publishing+52/6/202117/6/2026
IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to bypass security restrictions, caused by improper access control. By sending a specially-crafted request to the REST API, an attacker could exploit this vulnerability to bypass access restrictions, and execute arbitrary actions with…
AnalizadaAlta (8.1)99%⚠ Explotación activaApache StrutsCisco Digital Media ManagerCisco Hosted Collaboration SolutionCisco Media Experience Engine+315/9/201717/6/2026
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to Remote Code Execution when deserializing XML payloads.
ModificadaMedia (5.8)1.1%—Cisco Digital Media Manager12/9/201316/6/2026
Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCub23849.
ModificadaAlta (9)3.2%—Cisco Digital Media Manager19/1/201216/6/2026
Cisco Digital Media Manager 5.2.2 and earlier, and 5.2.3, allows remote authenticated users to execute arbitrary code via vectors involving a URL and an administrative resource, aka Bug ID CSCts63878.
ModificadaAlta (7.1)2.5%—Cisco Digital Media Manager5/3/201016/6/2026
Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050.
ModificadaAlta (8.5)2.8%—Cisco Digital Media Manager5/3/201016/6/2026
Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vectors, and consequently execute arbitrary code via a crafted web application, aka Bug ID CSCtc46008.
ModificadaAlta (10)4.5%—Cisco Digital Media Manager5/3/201016/6/2026
Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x has a default password for the Tomcat administration account, which makes it easier for remote attackers to execute arbitrary code via a crafted web application, aka Bug ID CSCta03378.
ModificadaMedia (6.8)3.0%—North Country Public Radio Public Media Manager1/10/200716/6/2026
PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Manager (PMM) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the indir parameter.