Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul News Portal | 18/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/aboutus.php. The manipulation of the argument pagetitle leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.54% | — | Campcodes Online Shopping Portal | 18/5/2025 | 17/6/2026 | A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot-password.php. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul News Portal | 18/5/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul News Portal Project 4.1 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/contactus.php. The manipulation of the argument pagetitle leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.58% | — | Phpgurukul News Portal | 18/5/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul News Portal 4.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.40% | — | Advayasoftech Gems ERP Portal | 18/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Advaya Softech GEMS ERP Portal 2.1. This affects an unknown part of the file /studentLogin/studentLogin.action. The manipulation of the argument userId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.9) | 0.55% | — | Mayurik Best Online News Portal | 15/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Best Online News Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /search.php. The manipulation of the argument searchtitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+1 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Simatic PCS NEOSiemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation Portal+1 | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Analizada | Alta (8.7) | 0.62% | — | Siemens Sinec NMSSiemens Sinema Remote ConnectSiemens Totally Integrated Automation PortalSiemens User Management Component | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SINEC NMS (All versions < V4.0), SINEMA Remote Connect (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All… | |
| Aplazada | Crítica (9.3) | 0.30% | — | Pixmeo Osirix MD WEB PortalAI | 8/5/2025 | 17/6/2026 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials. | |
| Aplazada | Alta (8.7) | 0.63% | — | Arista Cloudvision PortalAI | 8/5/2025 | 17/6/2026 | On affected versions of the Arista CloudVision Portal (CVP on-prem), the time-bound device onboarding token can be used to gain admin privileges on CloudVision. | |
| Aplazada | Crítica (10) | 0.78% | — | Arista Cloudvision PortalAI | 8/5/2025 | 17/6/2026 | On affected versions of the CloudVision Portal, improper access controls could enable a malicious authenticated user to take broader actions on managed EOS devices than intended. This advisory impacts the Arista CloudVision Portal products when run on-premise. It does not impact CloudVision as-a-Service. | |
| Analizada | Media (6.9) | 3.8% | 💥 Exploit | Liferay Digital Experience PlatformLiferay Portal | 6/5/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.5, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 7.4 GA through update 92 allows an remote non-authenticated attacker to inject… | |
| Analizada | Alta (8.8) | 0.48% | — | Lopalopa Online Service Management Portal | 5/5/2025 | 17/6/2026 | kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the checkid parameter. | |
| Analizada | Alta (8.8) | 0.48% | — | Lopalopa Online Service Management Portal | 5/5/2025 | 17/6/2026 | kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.php via the parameter: rPassword. | |
| Analizada | Media (5.3) | 0.40% | — | Lopalopa Online Service Management Portal | 5/5/2025 | 17/6/2026 | A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0. | |
| Analizada | Media (6.9) | 0.52% | — | Phpgurukul Emergency Ambulance Hiring Portal | 5/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.52% | — | Phpgurukul Emergency Ambulance Hiring Portal | 5/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/edit-ambulance.php. The manipulation of the argument dconnum leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (6.5) | 1.9% | 💥 Exploit | Mojoportal | 21/4/2025 | 17/6/2026 | mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey. | |
| Aplazada | Alta (7.1) | 0.29% | — | Clinked Client PortalAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clinked Clinked Client Portal clinked-client-portal allows Reflected XSS.This issue affects Clinked Client Portal: from n/a through <= 1.10. | |
| Analizada | Media (4.8) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 17/4/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists with radio button type custom fields in Liferay Portal 7.2.0 through 7.4.3.129, and Liferay DXP 2024.Q4.1 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.9, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through… | |
| Analizada | Media (6.9) | 0.31% | — | Growatt Cloud Portal | 15/4/2025 | 17/6/2026 | An unauthenticated attacker can obtain EV charger energy consumption information of other users. | |
| Analizada | Media (6.9) | 0.58% | — | Growatt Cloud Portal | 15/4/2025 | 17/6/2026 | An unauthenticated attacker can obtain other users' charger information. | |
| Analizada | Media (6.9) | 0.30% | — | Growatt Cloud Portal | 15/4/2025 | 17/6/2026 | An attacker can get information about the groups of the smart home devices for arbitrary users (i.e., "rooms"). | |
| Analizada | Media (6.9) | 0.54% | — | Growatt Cloud Portal | 15/4/2025 | 17/6/2026 | Unauthenticated attackers can trigger device actions associated with specific "scenes" of arbitrary users. |