Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
3955 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+169 | 24/9/2025 | 25/9/2026 | Revelación de información cuando el UE recibe el paquete RTP de la red, mientras decodifica y reensambla los fragmentos del paquete RTP. | |
| Analizada | Alta (7.1) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+283 | 24/9/2025 | 25/9/2026 | Problema criptográfico al realizar la decodificación del relleno PKCS RSA. | |
| Analizada | Media (5.3) | 0.18% | — | Liferay Digital Experience PlatformLiferay Portal | 24/9/2025 | 17/6/2026 | Una vulnerabilidad de Expiración de Sesión Insuficiente en Liferay Portal 7.4.3.121 hasta 7.3.3.131, y Liferay DXP 2024.Q4.0 hasta 2024.Q4.3, 2024.Q3.1 hasta 2024.Q3.13, 2024.Q2.0 hasta 2024.Q2.13, y 2024.Q1.1 hasta 2024.Q1.12 permite a un atacante remoto no autenticado reutilizar una sesión de usuario antigua… | |
| Analizada | Media (6.9) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 23/9/2025 | 25/9/2026 | Una vulnerabilidad de cross-site scripting (XSS) reflejada en Liferay Portal 7.4.0 hasta 7.4.3.112, y Liferay DXP 2024.Q1.1 hasta 2024.Q1.18 y 7.4 GA hasta la actualización 92 permite a un atacante remoto autenticado inyectar código JavaScript a través del parámetro… | |
| Aplazada | Media (4.3) | 0.22% | — | SAP BI PlatformAI | 23/9/2025 | 17/6/2026 | SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system. | |
| Analizada | Baja (2.1) | 0.35% | — | Fuyang Lipengjun Platform | 23/9/2025 | 17/6/2026 | A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the file /sys/smslog/queryAll. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.35% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a… | |
| Analizada | Media (5.3) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to add a note to an order in… | |
| Analizada | Baja (2.1) | 0.35% | — | Fuyang Lipengjun Platform | 22/9/2025 | 17/6/2026 | A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of the file /topiccategory/queryAll. This manipulation causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 22/9/2025 | 17/6/2026 | A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /topic/queryAll. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.3) | 0.25% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 22/9/2025 | 30/9/2026 | Una vulnerabilidad de seguridad ha sido detectada en la plataforma fuyang_lipengjun 1.0. Este problema afecta la función UserCouponController del archivo /usercoupon/queryAll. La manipulación conduce a una autorización indebida. La explotación remota del ataque es posible. El exploit ha sido divulgado públicamente y… | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected… | |
| Aplazada | Alta (8.8) | 0.29% | — | Boodskap IOT PlatformAI | 22/9/2025 | 17/6/2026 | Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department | |
| Aplazada | Crítica (9.8) | 0.53% | — | Aikaan IOT Management PlatformAI | 22/9/2025 | 17/6/2026 | Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot into other connected IoT devices. This can lead to remote code… | |
| Aplazada | Media (5.4) | 0.31% | — | Horato Internet Technologies Ind. AND Trade INC Virtual Library PlatformAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Internet Technologies Ind. And Trade Inc. Virtual Library Platform allows Reflected XSS. This issue affects Virtual Library Platform: before v202. | |
| Aplazada | Alta (7.1) | 0.38% | — | Sitecore Experience ManagerAISitecore Experience PlatformAI | 21/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform… | |
| Analizada | Media (6.9) | 0.37% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote… | |
| Analizada | Media (5.1) | 0.18% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions allows remote attackers… | |
| Analizada | Media (6.9) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to… | |
| Analizada | Crítica (9.1) | 0.74% | — | Accela Automation Platform | 19/9/2025 | 17/6/2026 | Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request… | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 18/9/2025 | 17/6/2026 | A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 18/9/2025 | 17/6/2026 | A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 18/9/2025 | 17/6/2026 | A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.1) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 16/9/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter. |