Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
3955 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 8/10/2025 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into (1) a user’s… | |
| Analizada | Media (5.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 8/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 8/10/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 8/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload… | |
| Aplazada | Crítica (9.3) | 2.7% | 💥 Exploit | Melistechnology Melis PlatformAI | 8/10/2025 | 8/10/2026 | Carga de archivos que conduce a ejecución remota de código (RCE) en el módulo 'melis-cms-slider' de la Plataforma Melis de Melis Technology. Esta vulnerabilidad permite a un atacante cargar un archivo malicioso a través de una solicitud POST a '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' utilizando el… | |
| Aplazada | Crítica (9.3) | 0.33% | 💥 PoC | Melistechnology Melis PlatformAI | 8/10/2025 | 8/10/2026 | Vulnerabilidad en el módulo melis-core de la Plataforma Melis de Melis Technology, que, si se explota, permite a un atacante no autenticado crear una cuenta de administrador a través de una solicitud a '/melis/MelisCore/ToolUser/addNewUser'. | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 7/10/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 7/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a… | |
| Analizada | Media (4.8) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 6/10/2025 | 17/6/2026 | The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated… | |
| Aplazada | Crítica (9.3) | 2.4% | 💥 Exploit | Xwiki PlatformAI | 6/10/2025 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The specified value is added twice in the… | |
| Aplazada | Media (5.5) | 0.69% | — | Four-faith Water Conservancy Informatization PlatformAI | 6/10/2025 | 17/6/2026 | A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneReport/index.do/../../aloneReport/download.do;othersusrlogout.do. Performing manipulation of the argument fileName results in path traversal. It is possible to initiate the… | |
| Aplazada | Media (5.5) | 0.69% | — | Four-faith Water Conservancy Informatization PlatformAI | 6/10/2025 | 17/6/2026 | A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown functionality of the file /stAlarmConfigure/index.do/../../aloneReport/download.do;otherlogout.do. Such manipulation of the argument fileName leads to path traversal.… | |
| Analizada | Media (4.6) | 0.30% | — | Liferay Digital Experience PlatformLiferay Portal | 3/10/2025 | 17/6/2026 | A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Risc Zero Risc0 Zkvm PlatformAIRisc Zero Risc0 AggregationAIRisc Zero Risc0 Zkos V1compatAIRisc Zero Risc0 ZkvmAI | 2/10/2025 | 17/6/2026 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This… | |
| Aplazada | Alta (8.8) | 0.34% | — | Kissflow Work PlatformAI | 1/10/2025 | 5/7/2026 | A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Alta (8.8) | 0.47% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an… | |
| Analizada | Media (4.9) | 0.56% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint,… | |
| Analizada | Media (6.5) | 0.30% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the… | |
| Analizada | Media (5.4) | 0.36% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved… | |
| Analizada | Media (5.4) | 0.36% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the… | |
| Analizada | Media (6.5) | 0.44% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 30/9/2025 | 17/6/2026 | Vulnerabilidades de cross-site scripting (XSS) almacenadas en la traducción de Contenido Web en Liferay Portal 7.4.0 hasta 7.4.3.112, y versiones anteriores no compatibles, y Liferay DXP 2023.Q4.0 hasta 2023.Q4.8, 2023.Q3.1 hasta 2023.Q3.10, 7.4 GA hasta la actualización 92, y versiones anteriores no compatibles,… | |
| Analizada | Media (5.3) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 30/9/2025 | 17/6/2026 | Vulnerabilidad de Referencia Directa a Objeto Insegura (IDOR) con eventos de auditoría en Liferay Portal 7.4.0 hasta 7.4.3.117, y versiones antiguas no compatibles, y Liferay DXP 2024.Q1.1 hasta 2024.Q1.5, 2023.Q4.0 hasta 2023.Q4.10, 2023.Q3.1 hasta 2023.Q3.10, 7.4 GA hasta la actualización 92, y versiones antiguas no… | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1)… | |
| Analizada | Media (6.9) | 0.50% | — | Liferay Digital Experience PlatformLiferay Portal | 29/9/2025 | 17/6/2026 | Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows… |