Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

99 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.3)0.25%—IBM Sterling Partner Engagement Manager Essentials EditionAIIBM Sterling Partner Engagement Manager Standard EditionAI18/9/202618/9/2026
IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of service in the email service due to improper control of…
AplazadaMedia (6.5)0.45%—Icegram EngageAI1/8/202612/8/2026
The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injection via 'messages[][id]' Parameter in all versions up to, and including, 3.1.42 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
AplazadaAlta (7.4)0.28%—PushengageAI17/6/202617/6/2026
Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget <= 4.2.3 versions.
AnalizadaCrítica (9.3)0.38%—Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+427/5/202617/6/2026
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
Pendiente de análisisCrítica (9.4)0.41%—Salesforce Marketing Cloud EngagementAI23/3/202617/6/2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 30th, 2026.
Pendiente de análisisAlta (8.8)0.46%—Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI18/3/202617/6/2026
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports…
AnalizadaMedia (5.9)0.21%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques.
AnalizadaAlta (7.5)0.33%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information when detailed technical error messages are returned. This information could be used in further attacks against the system.
AnalizadaAlta (7.5)0.17%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access token
AnalizadaAlta (7.5)0.18%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
ModificadaMedia (5.4)0.21%—IBM Sterling Partner Engagement Manager13/3/202617/6/2026
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
AplazadaAlta (7.5)0.51%—Umbraco EngageAI26/2/202617/6/2026
Umbraco Engage is a business intelligence platform. A vulnerability has been identified in Umbraco Engage prior to versions 16.2.1 and 17.1.1 where certain API endpoints are exposed without enforcing authentication or authorization checks. The affected endpoints can be accessed directly over the network without…
AnalizadaMedia (6.6)0.16%—Tanium Engage5/2/202617/6/2026
Tanium addressed a documentation issue in Engage.
AnalizadaCrítica (9.8)0.62%—Salesforce Marketing Cloud Engagement24/1/202617/6/2026
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
AnalizadaCrítica (9.8)0.43%—Salesforce Marketing Cloud Engagement24/1/202617/6/2026
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As Webpage modules) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January…
AnalizadaCrítica (9.8)0.66%—Salesforce Marketing Cloud Engagement24/1/202617/6/2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (CloudPagesUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
AnalizadaCrítica (9.8)0.66%—Salesforce Marketing Cloud Engagement24/1/202617/6/2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Salesforce Marketing Cloud Engagement (MicrositeUrl module) allows Web Services Protocol Manipulation. This issue affects Marketing Cloud Engagement: before January 21st, 2026.
AplazadaAlta (7.1)0.19%—Perx Customer Engagement AND Loyalty PlatformAI27/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in the LMT Dashboard of the Perx Customer Engagement & Loyalty Platform allows an authenticated attacker to execute arbitrary JavaScript code in a victim's browser. The vulnerability is due to improper sanitization of SVG file uploads. An attacker can upload a malicious…
AplazadaAlta (7.5)0.62%—Roxnor FundengageAI20/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Roxnor FundEngine wp-fundraising-donation allows PHP Local File Inclusion.This issue affects FundEngine: from n/a through <= 1.7.4.
AplazadaMedia (4.3)0.15%—Slickstream Slick-engagementAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Slickstream Slickstream slick-engagement allows Cross Site Request Forgery.This issue affects Slickstream: from n/a through <= 2.0.3.
AnalizadaAlta (8.2)0.58%—Microsoft Nuance Digital Engagement Platform10/6/202517/6/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network.
AnalizadaMedia (4.8)0.31%—Icegram Engage15/5/202517/6/2026
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaMedia (4.8)0.30%—Icegram Engage15/5/202517/6/2026
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
AnalizadaAlta (7.5)0.35%—IBM Sterling Partner Engagement Manager7/5/202517/6/2026
IBM Sterling Partner Engagement Manager 6.1.0, 6.2.0, 6.2.2 JWT secret is stored in public Helm Charts and is not stored as a Kubernetes secret.
AnalizadaAlta (7.1)0.63%—Elementengage Simple Certain Time TO Show Content26/2/202517/6/2026
The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.