Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
3955 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 13/10/2025 | 17/6/2026 | Liferay Portal 7.3.0 through 7.4.3.119, and Liferay DXP 2023.Q3.1 through 2023.Q3.8, 2023.Q4.0 through 2023.Q4.5, 7.4 GA through update 92 and 7.3 GA though update 36 shows content to users who do not have permission to view it via the Menu Display Widget. This security flaw could result in sensitive information being… | |
| Analizada | Media (5.3) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 13/10/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote authenticated users in one virtual instance… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 13/10/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions allow remote authenticated users to inject arbitrary… | |
| Analizada | Media (5.3) | 0.30% | — | Liferay Digital Experience PlatformLiferay Portal | 13/10/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability with account addresses in Liferay Portal 7.4.3.4 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated users to from one account to view addresses from a different… | |
| Analizada | Media (5.3) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 13/10/2025 | 17/6/2026 | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote authenticated attackers to view publication comments via the… | |
| Analizada | Media (5.3) | 0.27% | — | Liferay Digital Experience Platform | 13/10/2025 | 8/10/2026 | Vulnerabilidad de Insecure Direct Object Reference (IDOR) con direcciones de envío en Liferay DXP 2023.Q4.1 hasta 2023.Q4.5 permite a usuarios autenticados remotos desde una instancia virtual ver las direcciones de envío de una instancia virtual diferente a través del parámetro… | |
| Analizada | Media (4.8) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 13/10/2025 | 17/6/2026 | Insecure direct object reference (IDOR) vulnerability in Publications in Liferay Portal 7.3.1 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92, and 7.3 GA through update 36 allows remote authenticated attackers to view the edit page of a… | |
| Analizada | Media (5.1) | 0.19% | — | Liferay Digital Experience PlatformLiferay Portal | 10/10/2025 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Liferay Portal 7.4.1 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to add and edit publication comments. | |
| Analizada | Media (4.6) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 10/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or HTML via the crafted… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 10/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 21 through update 92 allows remote authenticated attackers to inject arbitrary web script or… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 10/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 8 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload… | |
| Aplazada | Media (5.3) | 0.36% | — | Servicenow AI PlatformAI | 10/10/2025 | 8/10/2026 | ServiceNow ha abordado una vulnerabilidad de cross-site scripting reflejado que fue identificada en la Plataforma de IA de ServiceNow. Esta vulnerabilidad podría resultar en la ejecución de código arbitrario dentro de los navegadores de los usuarios de ServiceNow que hagan clic en un enlace especialmente diseñado.… | |
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Servicenow AI PlatformAI | 10/10/2025 | 8/10/2026 | ServiceNow ha abordado una vulnerabilidad de cross-site scripting reflejado que fue identificada en la Plataforma de IA de ServiceNow. Esta vulnerabilidad podría resultar en la ejecución de código arbitrario dentro de los navegadores de los usuarios de ServiceNow que hagan clic en un enlace especialmente diseñado.… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 9/10/2025 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 update 35 through update 92, and 7.3 update 25 through update 36 allow remote attackers to inject arbitrary web script or… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+23 | 9/10/2025 | 8/10/2026 | Corrupción de memoria al invocar llamadas IOCTL de procedimiento remoto. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qmp1000 Firmware+34 | 9/10/2025 | 8/10/2026 | Corrupción de memoria al asignar búferes en el servicio DSP. | |
| Analizada | Alta (7.1) | 0.17% | — | Qualcomm Qcc5161 FirmwareQualcomm Qcc7225 FirmwareQualcomm Qcc7226 FirmwareQualcomm Qcc7228 Firmware+4 | 9/10/2025 | 8/10/2026 | DoS transitorio puede ocurrir cuando surge concurrencia multiperfil con QHS habilitado. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+27 | 9/10/2025 | 8/10/2026 | corrupción de memoria al procesar un evento de finalización de codificación de imagen. | |
| Analizada | Alta (8.8) | 0.09% | — | Qualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform FirmwareQualcomm Immersive Home 318 Platform Firmware+21 | 9/10/2025 | 8/10/2026 | Corrupción de memoria al realizar una llamada SCM con entradas malformadas. | |
| Analizada | Alta (8.8) | 0.09% | — | Qualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform FirmwareQualcomm Immersive Home 318 Platform Firmware+21 | 9/10/2025 | 8/10/2026 | Corrupción de memoria al realizar una llamada SCM. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 Firmware+295 | 9/10/2025 | 8/10/2026 | Corrupción de memoria al procesar un archivo de licencia malformado durante el reinicio. | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+315 | 9/10/2025 | 8/10/2026 | Corrupción de memoria durante el caso de uso de la aplicación PlayReady mientras se procesan comandos TA. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qcc2072 Firmware+27 | 9/10/2025 | 8/10/2026 | DoS transitorio mientras se procesa una llamada IOCTL para la codificación de imágenes. | |
| Analizada | Media (5.5) | 0.08% | — | Qualcomm Ar8035 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Qca6174a Firmware+59 | 9/10/2025 | 8/10/2026 | DoS transitorio mientras se procesan paquetes de video recibidos del firmware de video. | |
| Analizada | Media (6.5) | 0.08% | — | Qualcomm Csr8811 FirmwareQualcomm Immersive Home 214 Platform FirmwareQualcomm Immersive Home 216 Platform FirmwareQualcomm Immersive Home 316 Platform Firmware+61 | 9/10/2025 | 8/10/2026 | Revelación de información puede ocurrir al procesar el registro del hipervisor. |