Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1268 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.57%—Liferay Digital Experience PlatformLiferay DXPLiferay Portal8/2/202417/6/2026
The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS)…
ModificadaMedia (4.6)0.31%—Liferay Digital Experience PlatformLiferay Portal8/2/202417/6/2026
Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked.
ModificadaMedia (5.4)0.56%—Liferay Digital Experience PlatformLiferay DXPLiferay Portal7/2/202417/6/2026
Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to…
ModificadaMedia (6.5)0.69%—Liferay Digital Experience PlatformLiferay Portal7/2/202417/6/2026
The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a…
ModificadaAlta (8.8)0.29%—Imoulife Imou GO6/2/202417/6/2026
An issue in the com.oneed.dvr.service.DownloadFirmwareService component of IMOU GO v1.0.11 allows attackers to force the download of arbitrary files.
ModificadaMedia (5.4)0.33%—Awplife Event Monster21/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.
ModificadaMedia (5.4)0.44%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271522.
ModificadaMedia (4.3)0.52%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to manipulate username data due to improper input validation. IBM X-Force ID: 271228.
ModificadaMedia (5.3)0.76%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 271197.
ModificadaCrítica (9.1)0.97%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view modify files on the system. IBM X-Force ID: 271196.
ModificadaAlta (8.8)0.84%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341.
ModificadaAlta (7.5)0.61%—IBM Security Guardium KEY Lifecycle Manager20/12/202317/6/2026
IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220.
ModificadaAlta (8.1)0.73%—Imoulife Imou Life19/12/202317/6/2026
A session hijacking vulnerability has been detected in the Imou Life application affecting version 6.7.0. This vulnerability could allow an attacker to hijack user accounts due to the QR code functionality not properly filtering codes when scanning a new device and directly running WebView without prompting or…
ModificadaMedia (5.5)1.9%—Fujitsu Esprimo D556/2 FirmwareFujitsu Esprimo D6011 FirmwareFujitsu Esprimo D6012 FirmwareFujitsu Esprimo D7010 Firmware+1837/12/202317/6/2026
A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of…
ModificadaMedia (6.1)0.65%—Liferay Portal17/11/202317/6/2026
Reflected cross-site scripting (XSS) vulnerability on a content page’s edit page in Liferay Portal 7.4.3.94 through 7.4.3.95 allows remote attackers to inject arbitrary web script or HTML via the `p_l_back_url_title` parameter.
ModificadaAlta (7.8)0.20%—Intel Battery Life Diagnostic Tool14/11/202317/6/2026
Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.23%—Intel Battery Life Diagnostic Tool14/11/202317/6/2026
Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel Battery Life Diagnostic Tool14/11/202317/6/2026
Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.4)2.3%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the Commerce module in Liferay Portal 7.3.5 through 7.4.3.91, and Liferay DXP 7.3 update 33 and earlier, and 7.4 before update 92 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a (1) Shipping Name, (2)…
ModificadaMedia (5.4)2.2%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay DXP 7.0 fix pack 83 through 102, 7.1 fix pack 28 and earlier, 7.2 fix pack 20 and earlier, 7.3 update 33 and earlier, and 7.4 before update 88 allows remote attackers to inject arbitrary web script…
ModificadaMedia (6.1)0.46%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Multiple reflected cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.89, and Liferay DXP 7.4 update 41 through update 89 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2)…
ModificadaMedia (5.4)0.46%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Stored cross-site scripting (XSS) vulnerability in Page Tree menu Liferay Portal 7.3.6 through 7.4.3.78, and Liferay DXP 7.3 fix pack 1 through update 23, and 7.4 before update 79 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into page's "Name" text field.
ModificadaMedia (5.4)0.46%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the fragment components in Liferay Portal 7.4.2 through 7.4.3.53, and Liferay DXP 7.4 before update 54 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into any non-HTML field of a linked source asset.
ModificadaMedia (5.4)2.2%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87, and Liferay DXP 7.4 before update 88 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a Vocabulary's 'description' text field.
ModificadaMedia (6.1)0.46%—Liferay Digital Experience PlatformLiferay Portal17/10/202317/6/2026
Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect`…
Orbitaley — Vulnerabilidades