Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

3955 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.21%—Liferay Digital Experience PlatformLiferay Portal8/10/202517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5 and 2023.Q3.1 through 2023.Q3.10 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into (1) a user’s…
AnalizadaMedia (5.1)0.24%—Liferay Digital Experience PlatformLiferay Portal8/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and 7.3 GA through update 35 allows remote attackers to inject arbitrary web script or HTML via a crafted payload…
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal8/10/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 18 through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted…
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal8/10/202517/6/2026
Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload…
AplazadaCrítica (9.3)2.7%💥 ExploitMelistechnology Melis PlatformAI8/10/20258/10/2026
Carga de archivos que conduce a ejecución remota de código (RCE) en el módulo 'melis-cms-slider' de la Plataforma Melis de Melis Technology. Esta vulnerabilidad permite a un atacante cargar un archivo malicioso a través de una solicitud POST a '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm' utilizando el…
AplazadaCrítica (9.3)0.33%💥 PoCMelistechnology Melis PlatformAI8/10/20258/10/2026
Vulnerabilidad en el módulo melis-core de la Plataforma Melis de Melis Technology, que, si se explota, permite a un atacante no autenticado crear una cuenta de administrador a través de una solicitud a '/melis/MelisCore/ToolUser/addNewUser'.
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal7/10/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms…
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal7/10/202517/6/2026
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a…
AnalizadaMedia (4.8)0.23%—Liferay Digital Experience PlatformLiferay Portal6/10/202517/6/2026
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated…
AplazadaCrítica (9.3)2.4%💥 ExploitXwiki PlatformAI6/10/202517/6/2026
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The specified value is added twice in the…
AplazadaMedia (5.5)0.69%—Four-faith Water Conservancy Informatization PlatformAI6/10/202517/6/2026
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneReport/index.do/../../aloneReport/download.do;othersusrlogout.do. Performing manipulation of the argument fileName results in path traversal. It is possible to initiate the…
AplazadaMedia (5.5)0.69%—Four-faith Water Conservancy Informatization PlatformAI6/10/202517/6/2026
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown functionality of the file /stAlarmConfigure/index.do/../../aloneReport/download.do;otherlogout.do. Such manipulation of the argument fileName leads to path traversal.…
AnalizadaMedia (4.6)0.30%—Liferay Digital Experience PlatformLiferay Portal3/10/202517/6/2026
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows…
AplazadaCrítica (9.3)0.46%—Risc Zero Risc0 Zkvm PlatformAIRisc Zero Risc0 AggregationAIRisc Zero Risc0 Zkos V1compatAIRisc Zero Risc0 ZkvmAI2/10/202517/6/2026
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This…
AplazadaAlta (8.8)0.34%—Kissflow Work PlatformAI1/10/20255/7/2026
A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaAlta (8.8)0.47%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an…
AnalizadaMedia (4.9)0.56%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint,…
AnalizadaMedia (6.5)0.30%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the…
AnalizadaMedia (5.4)0.36%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved…
AnalizadaMedia (5.4)0.36%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the…
AnalizadaMedia (6.5)0.44%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in…
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal30/9/202517/6/2026
Vulnerabilidades de cross-site scripting (XSS) almacenadas en la traducción de Contenido Web en Liferay Portal 7.4.0 hasta 7.4.3.112, y versiones anteriores no compatibles, y Liferay DXP 2023.Q4.0 hasta 2023.Q4.8, 2023.Q3.1 hasta 2023.Q3.10, 7.4 GA hasta la actualización 92, y versiones anteriores no compatibles,…
AnalizadaMedia (5.3)0.29%—Liferay Digital Experience PlatformLiferay Portal30/9/202517/6/2026
Vulnerabilidad de Referencia Directa a Objeto Insegura (IDOR) con eventos de auditoría en Liferay Portal 7.4.0 hasta 7.4.3.117, y versiones antiguas no compatibles, y Liferay DXP 2024.Q1.1 hasta 2024.Q1.5, 2023.Q4.0 hasta 2023.Q4.10, 2023.Q3.1 hasta 2023.Q3.10, 7.4 GA hasta la actualización 92, y versiones antiguas no…
AnalizadaMedia (4.8)0.21%—Liferay Digital Experience PlatformLiferay Portal29/9/202517/6/2026
Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 74 through update 92 allow remote attackers to inject arbitrary web script or HTML via the `redirect` parameter to (1)…
AnalizadaMedia (6.9)0.50%—Liferay Digital Experience PlatformLiferay Portal29/9/202517/6/2026
Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.107, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.4, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows…