Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.46% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter. | |
| Analizada | Media (5.4) | 0.53% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL. | |
| Analizada | Media (5.4) | 0.52% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into… | |
| Analizada | Media (6.1) | 0.52% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's `Name` field. | |
| Analizada | Media (5.4) | 0.45% | — | Liferay Digital Experience PlatformLiferay Portal | 24/5/2023 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field. | |
| Modificada | Alta (7.3) | 0.22% | — | Valvesoftware Half-life | 23/5/2023 | 17/6/2026 | A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privileges by supplying crafted parameters. | |
| Modificada | Media (6.7) | 0.16% | — | Intel Battery Life Diagnostic ToolIntel Oneapi Base ToolkitIntel SOC Watch | 12/5/2023 | 17/6/2026 | Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.52% | — | Fetlife Rollout-ui | 11/5/2023 | 9/7/2026 | Cross Site Scripting (XSS) Vulnerability in Fetlife rollout-ui version 0.5, allows attackers to execute arbitrary code via a crafted url to the delete a feature functionality. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Liferay Portal | 16/4/2023 | 17/6/2026 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file. | |
| Modificada | Alta (8.8) | 0.40% | — | IBM Security KEY Lifecycle Manager | 22/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to perform actions that they should not have access to due to improper authorization. IBM X-Force ID: 247630. | |
| Modificada | Media (5.3) | 0.94% | — | IBM Security KEY Lifecycle Manager | 22/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247606. | |
| Modificada | Crítica (9.8) | 0.97% | — | IBM Security KEY Lifecycle Manager | 21/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 247597. | |
| Modificada | Alta (7.5) | 0.67% | — | IBM Security KEY Lifecycle Manager | 21/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an attacker to upload files that could be used in a denial of service attack due to incorrect authorization. IBM X-Force ID: 247629. | |
| Modificada | Media (5.5) | 0.17% | — | IBM Security KEY Lifecycle Manager | 21/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 247601. | |
| Modificada | Media (5.3) | 0.68% | — | IBM Security KEY Lifecycle Manager | 21/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 247618. | |
| Modificada | Media (4.3) | 0.48% | — | IBM Security KEY Lifecycle Manager | 21/3/2023 | 17/6/2026 | IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files. IBM X-Force ID: 247602. | |
| Modificada | Crítica (9.8) | 2.3% | — | Liferea Project Liferea | 11/3/2023 | 17/6/2026 | A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source with the input |date >/tmp/bad-item-link.txt leads to os command injection. The attack may be… | |
| Modificada | Media (6.1) | 0.53% | — | Ajaxlife Project Ajaxlife | 5/3/2023 | 16/6/2026 | A vulnerability has been found in cfire24 ajaxlife up to 0.3.2 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 0.3.3 is able to address this issue. The patch is identified as… | |
| Modificada | Crítica (9.8) | 0.47% | — | Huawei Hilink AI Life | 27/2/2023 | 17/6/2026 | A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions. | |
| Modificada | Crítica (9.8) | 0.47% | — | Huawei Hilink AI Life | 27/2/2023 | 17/6/2026 | A piece of Huawei whole-home intelligence software has an Incorrect Privilege Assignment vulnerability. Successful exploitation of this vulnerability could allow attackers to access restricted functions. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Battery Life Diagnostic Tool | 16/2/2023 | 17/6/2026 | Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Battery Life Diagnostic Tool | 16/2/2023 | 17/6/2026 | Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Battery Life Diagnostic Tool | 16/2/2023 | 17/6/2026 | Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.21% | — | Oracle Global Lifecycle Management Nextgen OUI Framework | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where… | |
| Modificada | Media (5.4) | 0.53% | — | Shoplazza Lifestyle | 18/12/2022 | 17/6/2026 | A vulnerability was found in Shoplazza LifeStyle 1.1. It has been rated as problematic. This issue affects some unknown processing of the file /admin/api/theme-edit/ of the component Review Flow Handler. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The… |