Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.80% | — | HP Life | 9/10/2023 | 17/6/2026 | HP LIFE Android Mobile application is potentially vulnerable to escalation of privilege and/or information disclosure. | |
| Modificada | Media (5.5) | 0.19% | — | IBM Collaborative Lifecycle ManagementIBM Engineering Lifecycle Management | 6/10/2023 | 17/6/2026 | IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitive version information to a user that could be used in further attacks against the system. IBM X-Force ID: 230498. | |
| Modificada | Media (5.4) | 0.51% | — | Awplife Blog Filter | 4/10/2023 | 17/6/2026 | The Blog Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'AWL-BlogFilter' shortcode in versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and… | |
| Modificada | Media (5.4) | 0.40% | — | Awplife Blog Filter | 30/9/2023 | 17/6/2026 | The Comments by Startbit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vivafbcomment' shortcode in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | |
| Modificada | Alta (8.8) | 1.3% | — | Didotech Engineering & Lifecycle Management | 15/9/2023 | 17/6/2026 | A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | |
| Modificada | Crítica (9.8) | 2.5% | 💥 PoC | Imoulife Life | 11/9/2023 | 17/6/2026 | The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and direct web content loading occurs. | |
| Analizada | Media (4.3) | 0.58% | — | Liferay Digital Experience PlatformLiferay Portal | 2/8/2023 | 17/6/2026 | The organization selector in Liferay Portal 7.4.3.81 through 7.4.3.85, and Liferay DXP 7.4 update 81 through 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations. | |
| Modificada | Media (5.4) | 0.36% | — | Oracle Agile Product Lifecycle Management | 18/7/2023 | 25/8/2026 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a… | |
| Modificada | Alta (8.8) | 0.27% | — | Awplife Album Gallery | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions. | |
| Modificada | Crítica (9.8) | 0.80% | — | Janobe Life Insurance Management System | 16/7/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Life Insurance Management System 1.0. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Alta (8.8) | 0.40% | — | Liferay DXPLiferay Portal | 15/6/2023 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the… | |
| Analizada | Media (6.1) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 15/6/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter. | |
| Modificada | Media (6.1) | 0.47% | — | Liferay DXPLiferay Portal | 15/6/2023 | 17/6/2026 | Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter. | |
| Modificada | Media (6.1) | 0.59% | — | Janobe Life Insurance Management System | 8/6/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Life Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file insertNominee.php of the component POST Parameter Handler. The manipulation of the argument nominee_id leads to cross site… | |
| Modificada | Alta (7.5) | 0.92% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs. | |
| Analizada | Alta (7.5) | 0.82% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property… | |
| Analizada | Alta (7.5) | 0.74% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL. | |
| Analizada | Media (4.3) | 0.61% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object… | |
| Analizada | Media (4.3) | 0.61% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page. | |
| Analizada | Alta (8.1) | 0.55% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when… | |
| Analizada | Media (6.1) | 0.53% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field. | |
| Analizada | Media (5.4) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job… | |
| Analizada | Media (5.4) | 0.53% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field. |