Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1268 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.7)0.25%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle…
AnalizadaAlta (7.5)0.26%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.
AnalizadaMedia (4.3)0.47%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
AnalizadaMedia (4.4)0.19%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
AnalizadaMedia (4.4)0.35%—IBM Security Guardium KEY Lifecycle Manager17/12/202417/6/2026
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
AplazadaBaja (3.3)0.19%—SAP Product Lifecycle Costing ClientAI10/12/202417/6/2026
SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being…
AplazadaMedia (6.5)0.63%—Code4life Database FOR CF7AI9/12/202417/6/2026
Missing Authorization vulnerability in code4life Database for CF7 database-for-cf7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Database for CF7: from n/a through <= 1.2.4.
AplazadaMedia (6.4)0.53%—Prestalife Product DesignerAI21/11/202417/6/2026
The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AnalizadaAlta (7.5)1.7%⚠ Explotación activaOracle Agile Product Lifecycle Management18/11/202417/6/2026
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM…
AnalizadaAlta (8.2)0.70%—IBM Engineering Lifecycle Optimization - Engineering Insights15/11/202417/6/2026
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaMedia (6.8)0.26%—Hitbytes Life8/11/202417/6/2026
An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
AnalizadaMedia (5.3)0.53%—Projectworlds Life Insurance Management System3/11/202417/6/2026
A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /editNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.53%—Projectworlds Life Insurance Management System3/11/202417/6/2026
A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /editPayment.php. The manipulation of the argument recipt_no leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaCrítica (9.8)0.39%—Kraftplugins Wheel OF Life1/11/202417/6/2026
Missing Authorization vulnerability in Kraft Plugins Wheel of Life wheel-of-life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through <= 1.1.8.
AplazadaAlta (8.4)0.20%—Dreamcatcher LifeAI24/10/202417/6/2026
Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.
AnalizadaMedia (6.1)0.24%—Liferay Digital Experience PlatformLiferay Portal22/10/202417/6/2026
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA through fix pack 28, 7.0 GA through fix pack 102 and 6.2 GA through fix pack 173 does not sufficiently protect against…
ModificadaAlta (8.8)0.65%—Liferay Digital Experience PlatformLiferay Portal22/10/202417/6/2026
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does not properly check user permissions before updating a workflow definition, which allows remote authenticated users to…
AnalizadaAlta (8.8)0.38%—Liferay Digital Experience PlatformLiferay Portal22/10/202417/6/2026
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.4.0 through 7.4.3.103, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 update 29 through update 35 allows remote attackers to (1) change user passwords, (2) shut…
AnalizadaAlta (8.8)0.38%—Liferay Digital Experience PlatformLiferay Portal22/10/202417/6/2026
Cross-site request forgery (CSRF) vulnerability in the content page editor in Liferay Portal 7.3.2 through 7.4.3.107, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 GA through update 92 and 7.3 GA through update 35 allows remote attackers to (1) change user passwords, (2) shut down the…
AnalizadaAlta (8.8)0.38%—Liferay Digital Experience PlatformLiferay Portal22/10/202417/6/2026
Cross-site request forgery (CSRF) vulnerability in the My Account widget in Liferay Portal 7.4.3.75 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.2, 2023.Q3.1 through 2023.Q3.5, 7.4 update 75 through update 92 and 7.3 update 32 through update 36 allows remote attackers to (1) change user passwords, (2)…
AplazadaMedia (5.4)0.17%—Awplife Contact Form WidgetAI17/10/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Site Request Forgery.This issue affects Contact Form Widget: from n/a through <= 1.4.2.
AplazadaMedia (5.3)0.17%—Opentext Application Lifecycle ManagementAIOpentext Quality CenterAI16/10/202417/6/2026
Untrusted Search Path vulnerability in OpenText™ Application Lifecycle Management (ALM),Quality Center allows Code Inclusion. The vulnerability allows a user to archive a malicious DLLs on the system prior to the installation. This issue affects Application Lifecycle Management (ALM),Quality Center: 15.00, 15.01,…
AplazadaMedia (5.3)0.28%—Com.ilife.home.globalAI14/10/202417/6/2026
An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.
AplazadaAlta (7.5)0.52%—Hubble Connected VervelifeAI14/10/202417/6/2026
An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.
AnalizadaMedia (5.3)0.37%—Nafisulbari Life Insurance Management System27/8/202417/6/2026
A vulnerability, which was classified as critical, has been found in nafisulbari/itsourcecode Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file editPayment.php of the component Payment Handler. The manipulation of the argument recipt_no leads to improper access controls.…
Orbitaley — Vulnerabilidades