Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.71%💥 PoCCloudilyaerp BET E-portal9/1/202617/6/2026
BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.
AnalizadaCrítica (9.3)0.41%—Opexustech Ecase Portal8/1/202617/6/2026
OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.
AnalizadaBaja (2.1)0.37%—Advayasoftech Gems ERP Portal29/12/20257/10/2026
A security vulnerability has been detected in Advaya Softech GEMS ERP Portal up to 2.1. This affects an unknown part of the file /home.jsp?isError=true of the component Error Message Handler. The manipulation of the argument Message leads to cross site scripting. It is possible to initiate the attack remotely. The…
AplazadaMedia (4.4)0.24%—Wpjobportal WP JOB PortalAI12/12/20257/10/2026
The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.4.4. This is due to the plugin explicitly whitelisting the `<script>` tag in its `WPJOBPORTAL_ALLOWED_TAGS` configuration and using insufficient input sanitization when saving job descriptions.…
AplazadaMedia (6.5)0.36%—Wpjobportal WP JOB PortalAI11/12/20257/10/2026
The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUploadedFile' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which…
AnalizadaMedia (4.4)0.11%—Fortinet FortianalyzerFortinet FortimanagerFortinet FortiosFortinet Fortiportal11/12/20251/10/2026
A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions,…
AnalizadaMedia (6.5)0.31%—Fortinet Fortiportal9/12/202517/6/2026
An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGate device via crafted HTTP requests.
AnalizadaAlta (8.1)0.54%—Adata Mitarbeiter Portal9/12/202517/6/2026
Multiple Incorrect Access Control vulnerabilities in adata Software GmbH Mitarbeiterportal 2.15.2.0 allow remote authenticated, low-privileged users to carry out administrative functions and manipulate data of other users via unauthorized API calls.
ModificadaMedia (4.6)0.34%—Adata Mitarbeiter Portal9/12/202517/6/2026
A stored Cross Site Scripting (XSS) vulnerability in the bulletin board (SchwarzeBrett) in adata Software GmbH Mitarbeiter Portal 2.15.2.0 allows remote authenticated users to execute arbitrary JavaScript code in the web browser of other users via manipulation of the 'Inhalt' parameter of the…
AplazadaMedia (6.1)0.26%—SAP Netweaver Enterprise PortalAI9/12/20257/10/2026
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal, an unauthenticated attacker could inject malicious scripts that execute in the context of other users� browsers, allowing the attacker to steal session cookies, tokens, and other sensitive information. As a result, the vulnerability…
AplazadaMedia (5.3)0.27%—Voidek Employee PortalAI5/12/202517/6/2026
The Voidek Employee Portal plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 1.0.7. This makes it possible for unauthenticated attackers to perform several actions like registering an account, deleting users, and…
AnalizadaMedia (4.3)0.24%—Phpgurukul Online Shopping Portal25/11/202517/6/2026
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
AplazadaAlta (8.8)0.38%—Realty PortalAI21/11/202517/6/2026
The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'rp_save_property_settings' function in versions 0.1 to 0.4.1. This makes it possible for authenticated attackers, with Subscriber-level access and…
AnalizadaMedia (6.1)0.31%—Microsoft 365 Defender Portal20/11/202517/6/2026
Microsoft Defender Portal Spoofing Vulnerability
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.
AnalizadaMedia (5.4)0.22%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.
AnalizadaMedia (6.5)0.24%—Phpgurukul Online Shopping Portal17/11/202517/6/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.
AnalizadaCrítica (9.8)0.41%—Phpgurukul Online Shopping Portal17/11/202528/9/2026
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
AnalizadaMedia (6.1)0.22%—Radioinorr SVX Portal14/11/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php.
AnalizadaMedia (6)0.27%—Radioinorr SVX Portal14/11/202517/6/2026
SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php.
AplazadaMedia (6.5)0.26%—SAP Netweaver Enterprise PortalAI11/11/202517/6/2026
SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL used during JNDI lookup operations, enabling access to an unintended JNDI provider.�This could further lead to disclosure or modification of information about the server. There is no impact on…
AplazadaAlta (7.5)0.27%—Redhat 3scale Developer PortalAI6/11/202517/6/2026
A flaw was found in the 3scale Developer Portal. When creating or updating an account in the Developer Portal UI it is possible to modify fields explicitly configured as read-only or hidden, allowing an attacker to modify restricted information.
ModificadaBaja (2.9)0.59%—Phpgurukul News Portal3/11/202517/6/2026
A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high.…
Orbitaley — Vulnerabilidades