Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 14% | 💥 Exploit | Webkul COM Ultimateportfolio | 3/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Media (4.3) | 2.7% | — | HP Project AND Portfolio Management Center | 29/3/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in HP Project and Portfolio Management Center (PPMC, formerly Mercury IT Governance) 7.1 through SP10 and 7.5 through SP3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Joomplace COM Joomportfolio | 28/12/2009 | 16/6/2026 | SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the secid parameter in a showcat action to index.php. | |
| Modificada | Alta (9.3) | 24% | — | Microsoft Office ProjectMicrosoft Project Portfolio ServerMicrosoft Project Server | 9/12/2009 | 16/6/2026 | Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability." | |
| Modificada | Media (5) | 30% | — | Oracle JDKFedoraproject FedoraOpensuseSuse Linux Enterprise Server+5 | 6/8/2009 | 16/6/2026 | XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Wportfolio | 25/11/2008 | 16/6/2026 | The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified password and password_retype parameters. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Wportfolio | 25/11/2008 | 16/6/2026 | Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in admin/tmp/. | |
| Modificada | Alta (7.5) | 1.1% | — | Outshine Phportfolio | 30/9/2008 | 16/6/2026 | SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.7% | 💥 Exploit | Morgan IDS Next GEN Portfolio Manager | 8/8/2007 | 16/6/2026 | SQL injection vulnerability in default.asp in Next Gen Portfolio Manager allows remote attackers to execute arbitrary SQL commands via the (1) Users_Email or (2) Users_Password parameter in an ExecuteTheLogin action. | |
| Modificada | Alta (10) | 2.6% | — | Nortel ContivityNortel VPN Router 5000Nortel VPN Router Portfolio | 27/4/2007 | 16/6/2026 | Nortel VPN Router (aka Contivity) 1000, 2000, 4000, and 5000 before 5_05.149, 5_05.3xx before 5_05.304, and 6.x before 6_05.140 includes the FIPSecryptedtest1219 and FIPSunecryptedtest1219 default accounts in the LDAP template, which might allow remote attackers to access the private network. | |
| Modificada | Alta (9.3) | 3.4% | — | TKS Banking Solutions Eportfolio | 7/3/2007 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme. | |
| Modificada | Media (4.3) | 6.1% | 💥 Exploit | TKS Banking Solutions Eportfolio | 7/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to inject arbitrary web script or HTML via unspecified vectors that bypass the client-side protection scheme, one of which may be the q parameter to the search program. NOTE: some of these details… | |
| Modificada | Alta (7.5) | 2.6% | — | Arcserve BrightstorBroadcom Cleverpath PortalCleverpath Aion BPMCleverpath Portal+7 | 20/12/2006 | 16/6/2026 | Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are… | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. |