Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1222 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.39% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 45 through 92 allows remote attackers to redirect users to arbitrary external URLs via the… | |
| Modificada | Media (6.3) | 0.48% | — | Liferay Digital Experience PlatformLiferay Portal | 20/2/2024 | 17/6/2026 | Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page. | |
| Analizada | Media (6.1) | 0.31% | — | Digital-peak Dpcalendar | 15/2/2024 | 17/6/2026 | XSS vulnerability in DP Calendar component for Joomla. | |
| Modificada | Alta (8.1) | 0.55% | — | Liferay Digital Experience PlatformLiferay DXPLiferay Portal | 8/2/2024 | 17/6/2026 | In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported versions the `doAsUserId` URL parameter may get leaked when creating linked content using the WYSIWYG editor and while impersonating a user. This may allow… | |
| Modificada | Media (5.3) | 0.59% | — | Liferay Digital Experience PlatformLiferay DXPLiferay Portal | 8/2/2024 | 17/6/2026 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 18, and older unsupported versions returns with different responses depending on whether a site does not exist or if the user does not have permission to access the site, which allows… | |
| Modificada | Media (6.5) | 0.57% | — | Liferay Digital Experience PlatformLiferay DXPLiferay Portal | 8/2/2024 | 17/6/2026 | The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 6, 7.2 before fix pack 19, and older unsupported versions does not check the URL of the IFrame, which allows remote authenticated users to cause a denial-of-service (DoS)… | |
| Modificada | Media (4.6) | 0.31% | — | Liferay Digital Experience PlatformLiferay Portal | 8/2/2024 | 17/6/2026 | Account lockout in Liferay Portal 7.2.0 through 7.3.0, and older unsupported versions, and Liferay DXP 7.2 before fix pack 5, and older unsupported versions does not invalidate existing user sessions, which allows remote authenticated users to remain authenticated after an account has been locked. | |
| Modificada | Media (5.4) | 0.56% | — | Liferay Digital Experience PlatformLiferay DXPLiferay Portal | 7/2/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay DXP 7.4 before update 8, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to… | |
| Modificada | Media (6.5) | 0.69% | — | Liferay Digital Experience PlatformLiferay Portal | 7/2/2024 | 17/6/2026 | The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 13, and older unsupported versions, does not limit resource consumption when generating a preview image, which allows remote authenticated users to cause a… | |
| Modificada | Alta (7.5) | 0.56% | — | Sepidzdigitalmenu | 6/2/2024 | 17/6/2026 | A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of the file /Waiters. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (4.8) | 0.40% | — | Awesomemotive Easy Digital Downloads | 5/2/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Media (4.9) | 0.82% | — | Westerndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra FirmwareWesterndigital MY Cloud Mirror G2 Firmware+8 | 5/2/2024 | 17/6/2026 | An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My… | |
| Modificada | Media (5.5) | 0.24% | — | Westerndigital MY Cloud Pr2100 FirmwareWesterndigital MY Cloud Pr4100 FirmwareWesterndigital MY Cloud Ex4100 FirmwareWesterndigital MY Cloud EX2 Ultra Firmware+9 | 5/2/2024 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability that could allow a rogue server on the local network to modify its URL using another DNS address to point back to the loopback adapter. This could then allow the URL to exploit other vulnerabilities on the local server. This was addressed by fixing DNS addresses that… | |
| Modificada | Media (5.4) | 0.33% | — | Awesomemotive Easy Digital Downloads | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments… | |
| Modificada | Alta (7.5) | 0.52% | — | Snpdigital Salesking | 24/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15. | |
| Modificada | Alta (7.5) | 0.58% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web… | |
| Modificada | Alta (7.5) | 0.58% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of… | |
| Modificada | Alta (7.5) | 0.37% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and password from the web interface (Password… | |
| Modificada | Alta (7.5) | 0.37% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit this vulnerability by eavesdropping on the victim’s network traffic to extract username and password from the web interface (Login Page)… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Device Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Network Name (SSID) parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Preshared Phrase parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the L2TP/PPTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Remote endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web… |