Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.40% | — | Joomdonation EdocmanAI | 15/7/2026 | 23/7/2026 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthenticated SQL injection. | |
| Aplazada | Crítica (9.3) | 0.17% | — | Pcmanfm QTAI | 22/5/2026 | 23/7/2026 | An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code… | |
| Aplazada | Baja (3.2) | 0.13% | — | PcmanagerAI | 21/4/2026 | 17/6/2026 | PcManager is affected by type privilege bypass, successful exploitation of this vulnerability may affect service availability | |
| Analizada | Alta (8.8) | 0.33% | — | Opendocman | 5/4/2026 | 24/7/2026 | OpenDocMan 1.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'where' parameter. Attackers can send GET requests to search.php with malicious SQL payloads in the 'where' parameter to extract sensitive database information. | |
| Analizada | Media (6.8) | 0.12% | — | Lenovo Pcmanager | 11/3/2026 | 24/8/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a local authenticated user to terminate privileged processes. | |
| Analizada | Alta (7.4) | 0.19% | — | Tencent Pcmanager | 23/2/2026 | 17/6/2026 | A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition. | |
| Aplazada | Crítica (9.3) | 0.83% | — | Pcman FTP ServerAI | 12/12/2025 | 17/6/2026 | PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access. | |
| Analizada | Media (6.9) | 0.30% | — | Tcman GIM | 2/12/2025 | 25/9/2026 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetUserQuestionAndAnswer' in '/WS/PDAWebService.asmx'. | |
| Analizada | Media (6.9) | 0.30% | — | Tcman GIM | 2/12/2025 | 25/9/2026 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system. The vulnerability is exploitable through the 'pda:username' parameter with 'soapaction GetLastDatePasswordChange' in '/WS/PDAWebService.asmx'. | |
| Analizada | Alta (8.7) | 0.29% | — | Tcman GIM | 2/12/2025 | 25/9/2026 | SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'. | |
| Analizada | Alta (8.7) | 0.25% | — | Tcman GIM | 2/12/2025 | 17/6/2026 | Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker to determine whether a user exists on the system by using the 'pda:userId' and 'pda:newPassword' parameters with 'soapaction UnlockUser’ in '/WS/PDAWebService.asmx'. | |
| Analizada | Alta (8.5) | 0.15% | — | Lenovo Pcmanager | 15/10/2025 | 17/6/2026 | A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges. | |
| Analizada | Alta (8.5) | 0.15% | — | Lenovo Pcmanager | 15/10/2025 | 17/6/2026 | A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges. | |
| Analizada | Alta (8.5) | 0.12% | — | Lenovo Pcmanager | 18/8/2025 | 17/6/2026 | An improper permission vulnerability was reported in Lenovo PC Manager that could allow a local attacker to escalate privileges. | |
| Analizada | Alta (7.1) | 0.33% | — | Tcman GIM | 9/6/2025 | 17/6/2026 | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to create a user and assign it many privileges by sending a POST request to /PC/frmGestionUser.aspx/updateUser. | |
| Analizada | Alta (7.1) | 0.25% | — | Tcman GIM | 9/6/2025 | 17/6/2026 | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an unprivileged attacker to modify the permissions held by each of the application's users, including the user himself by sending a POST request to /PC/Options.aspx?Command=2&Page=-1. | |
| Analizada | Alta (7.1) | 0.27% | — | Tcman GIM | 9/6/2025 | 17/6/2026 | Incorrect authorization vulnerability in TCMAN's GIM v11. This vulnerability allows an attacker, with low privilege level, to change the password of other users through a POST request using the parameters idUser, PasswordActual, PasswordNew and PasswordNewRepeat in /PC/WebService.aspx/validateChangePassword%C3%B1a. To… | |
| Analizada | Media (6.9) | 0.67% | — | Pcman FTP Server | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component SYSTEM Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.67% | — | Pcman FTP Server | 5/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component SET Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.71% | — | Pcman FTP Server | 5/6/2025 | 19/8/2026 | A vulnerability classified as critical was found in PCMan FTP Server 2.0.7. This vulnerability affects unknown code of the component PLS Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.71% | — | Pcman FTP Server | 5/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the component NOOP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.13% | — | Lenovo Pcmanager | 30/5/2025 | 17/6/2026 | An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user. | |
| Analizada | Alta (8.5) | 0.20% | — | Lenovo Pcmanager | 30/5/2025 | 17/6/2026 | An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. | |
| Analizada | Alta (8.5) | 0.18% | — | Lenovo Pcmanager | 30/5/2025 | 17/6/2026 | An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges. | |
| Analizada | Media (6.9) | 0.74% | — | Pcman FTP Server | 29/5/2025 | 19/8/2026 | A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |