Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.33%—Radioinorr Svxportal20/2/202614/7/2026
SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the stationid query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value into a hidden input value field, allowing attacker-supplied…
AnalizadaMedia (5.1)0.28%—Radioinorr Svxportal20/2/202614/7/2026
SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value directly into an HTML input value attribute, allowing attacker-supplied…
AnalizadaMedia (5.1)0.36%—Radioinorr Svxportal20/2/202614/7/2026
SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query parameter. The application embeds the unsanitized parameter value directly into an HTML input value attribute, allowing an unauthenticated remote attacker to inject and execute arbitrary JavaScript in…
AplazadaAlta (7.5)0.25%—Wpjobportal WP JOB PortalAI20/2/202617/6/2026
Missing Authorization vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.4.
AplazadaMedia (4.3)0.19%—Cozmoslabs Client PortalAI19/2/202617/6/2026
Missing Authorization vulnerability in madalin.ungureanu Client Portal client-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Portal: from n/a through <= 1.2.1.
AnalizadaMedia (5.5)0.15%—Tanium Enforce Recovery KEY Portal18/2/202617/6/2026
Tanium addressed an insecure file permissions vulnerability in Enforce Recovery Key Portal.
AplazadaCrítica (10)0.67%—MojoportalAI13/2/202617/6/2026
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
AnalizadaAlta (7.5)0.29%—Sunbirded-portal11/2/202617/6/2026
An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP request options
ModificadaMedia (5.5)0.47%—Clive 21 News Portal Project9/2/202617/6/2026
A flaw has been found in itsourcecode News Portal Project 1.0. This vulnerability affects unknown code of the file /admin/index.php of the component Administrator Login. This manipulation of the argument email causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
AnalizadaBaja (2)0.36%—Clive 21 News Portal Project8/2/202617/6/2026
A vulnerability was determined in itsourcecode News Portal Project 1.0. This affects an unknown part of the file /admin/aboutus.php. This manipulation of the argument pagetitle causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AnalizadaMedia (6.9)0.43%—Carmelo Student WEB Portal8/2/202617/6/2026
A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely.
AnalizadaMedia (5.5)0.47%—Bontrofftech Medical Center Portal Management System6/2/202617/6/2026
A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (5.5)0.38%—Bontrofftech Medical Center Portal Management System6/2/202617/6/2026
A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
AnalizadaMedia (6.1)0.29%—GhostGhost Portal27/1/202617/6/2026
Ghost is an open source content management system. In Ghost versions 5.43.0 through 5.12.04 and 6.0.0 through 6.14.0, an attacker was able to craft a malicious link that, when accessed by an authenticated staff user or member, would execute JavaScript with the victim's permissions, potentially leading to account…
AnalizadaMedia (4.8)0.25%—Wellchoose Single Sign-on Portal System26/1/202617/6/2026
Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
AnalizadaAlta (8.7)1.4%—Wellchoose Single Sign-on Portal System26/1/202617/6/2026
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AnalizadaAlta (8.7)1.4%—Wellchoose Single Sign-on Portal System26/1/202617/6/2026
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.
AnalizadaBaja (2)0.47%—Phpgurukul News Portal26/1/202617/6/2026
A vulnerability was identified in PHPGurukul News Portal 1.0. This affects an unknown part of the component Profile Pic Handler. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
AplazadaMedia (6.5)0.27%—Wpjobportal WP JOB PortalAI22/1/202617/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in wpjobportal WP Job Portal wp-job-portal allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Job Portal: from n/a through <= 2.4.3.
AnalizadaBaja (2.1)0.23%—Phpgurukul News Portal19/1/202617/6/2026
A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
ModificadaBaja (2.1)0.34%—Phpgurukul News Portal19/1/202617/6/2026
A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used.
AnalizadaCrítica (9.8)0.59%—Phpgurukul News Portal13/1/202617/6/2026
phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
AnalizadaCrítica (9.8)0.46%—Phpgurukul News Portal13/1/202617/6/2026
phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
AnalizadaCrítica (9.1)0.45%—Phpgurukul News Portal13/1/202617/6/2026
phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.
AplazadaMedia (6.1)0.20%—SAP Netweaver Enterprise PortalAI13/1/202617/6/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the server response and executed in a user's browser when the crafted URL is visited, leading to theft of session information, manipulation of portal content, or user…