Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.35% | — | Easyupdatesmanager Easy Updates ManagerAI | 28/5/2026 | 17/6/2026 | The Easy Updates Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in versions up to, and including, 9.0.20 This is due to insufficient input sanitization and output escaping in the pagination() function. This makes it possible for attackers to inject arbitrary web… | |
| Analizada | Media (5.4) | 0.19% | — | Dell Update Manager Plugin | 7/2/2025 | 17/6/2026 | Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Media (4.7) | 0.13% | — | SAP Netweaver JavaAISAP Software Update ManagerAI | 12/11/2024 | 17/6/2026 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to… | |
| Analizada | Media (4.9) | 0.25% | — | Dell Openmanage Enterprise Update Manager | 8/5/2024 | 17/6/2026 | Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log file. A remote high privileged attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to… | |
| Modificada | Alta (7.8) | 0.40% | — | Otris Update Manager | 10/3/2022 | 17/6/2026 | otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000. | |
| Modificada | Media (6.7) | 0.13% | — | ABB Update Manager | 28/10/2021 | 17/6/2026 | A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | HPE Smart Update Manager | 30/4/2020 | 17/6/2026 | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at… | |
| Modificada | Media (4.3) | 0.89% | — | Easyupdatesmanager Easy Updates Manager | 27/8/2019 | 17/6/2026 | The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error. | |
| Modificada | Crítica (9.8) | 1.4% | — | HPE Smart Update Manager | 5/6/2019 | 17/6/2026 | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5. | |
| Modificada | Alta (7.8) | 0.32% | — | HPE Smart Update Manager | 5/6/2019 | 17/6/2026 | A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege. | |
| Modificada | Alta (7.2) | 0.39% | — | HPE Smart Update Manager | 10/12/2014 | 17/6/2026 | Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors. | |
| Modificada | Media (6.4) | 2.3% | — | Canonical Update-managerCanonical Ubuntu Linux | 27/4/2014 | 16/6/2026 | DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows… | |
| Modificada | Baja (1.9) | 0.33% | — | Canonical Update-managerCanonical Ubuntu Linux | 17/4/2014 | 16/6/2026 | DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a… | |
| Modificada | Alta (7.2) | 0.64% | — | HP Smart Update Manager | 16/3/2014 | 17/6/2026 | Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors. | |
| Modificada | Baja (2.1) | 0.35% | — | Gnome Update-manager-coreCanonical Ubuntu Linux | 7/6/2012 | 16/6/2026 | DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials. | |
| Modificada | Media (5) | 60% | 💥 Exploit | Vmware Vcenter Update Manager | 19/11/2011 | 16/6/2026 | The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified vectors, a related issue to CVE-2009-1523. |