Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.44%—Esri Portal FOR Arcgis21/7/202317/6/2026
There is a Cross-site Scripting vulnerability in Esri Portal for ArcGIS Sites in versions 10.9 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victims browser. The privileges required to execute this attack…
AnalizadaAlta (8.4)0.86%—Esri Portal FOR Arcgis21/7/202317/6/2026
There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS Sites versions 11.1 and below that may allow a remote, authenticated attacker with high‑privileged access to create a crafted link that is persisted within the site configuration. When accessed by a victim, the stored payload may…
ModificadaCrítica (9.1)0.68%—Phpgurukul Online Shopping Portal10/7/202317/6/2026
A vulnerability was found in PHPGurukul Online Shopping Portal 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Registration Page. The manipulation leads to improper restriction of excessive authentication attempts. The attack can be launched remotely.…
ModificadaMedia (6.1)0.46%—Catalystconnect Zoho CRM Client Portal27/6/202317/6/2026
The Catalyst Connect Zoho CRM Client Portal WordPress plugin before 2.1.0 does not sanitize and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admin.
ModificadaMedia (5.4)0.36%—Wpjobportal WP JOB Portal22/6/202317/6/2026
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Job Portal WP Job Portal – A Complete Job Board plugin <= 2.0.0 versions.
ModificadaAlta (8.8)0.40%—Liferay DXPLiferay Portal15/6/202317/6/2026
Cross-site request forgery (CSRF) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to execute arbitrary code in the scripting console via the…
AnalizadaMedia (6.1)0.45%—Liferay Digital Experience PlatformLiferay Portal15/6/202317/6/2026
Cross-site scripting (XSS) vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.73, and Liferay DXP 7.4 update 70 through 73 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
ModificadaMedia (6.1)0.47%—Liferay DXPLiferay Portal15/6/202317/6/2026
Open redirect vulnerability in the Layout module's SEO configuration in Liferay Portal 7.4.3.70 through 7.4.3.76, and Liferay DXP 7.4 update 70 through 76 allows remote attackers to redirect users to arbitrary external URLs via the `_com_liferay_layout_admin_web_portlet_GroupPagesPortlet_backURL` parameter.
ModificadaAlta (8.1)0.47%—Arista Cloudvision Portal13/6/202317/6/2026
On affected versions of the CloudVision Portal improper access controls on the connection from devices to CloudVision could enable a malicious actor with network access to CloudVision to get broader access to telemetry and configuration data within the system than intended. This advisory impacts the Arista CloudVision…
ModificadaMedia (5.5)0.12%—Siemens Totally Integrated Automation Portal13/6/202317/6/2026
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V15.1 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All…
ModificadaAlta (7.5)0.92%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attackers to consume an excessive amount of server resources via crafted request URLs.
AnalizadaAlta (7.5)0.82%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.2 and earlier the default configuration does not require users to verify their email address, which allows remote attackers to create accounts using fake email addresses or email addresses which they don't control. The portal property…
AnalizadaAlta (7.5)0.74%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
The Dynamic Data Mapping module in Liferay Portal 7.4.3.67, and Liferay DXP 7.4 update 67 does not limit Document and Media files which can be downloaded from a Form, which allows remote attackers to download any file from Document and Media via a crafted URL.
AnalizadaMedia (4.3)0.61%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.60, and Liferay DXP 7.4 before update 61 does not segment object definition by virtual instance in search which allows remote authenticated users in one virtual instance to view object definition from a second virtual instance by searching for the object…
AnalizadaMedia (4.3)0.61%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
The Object module in Liferay Portal 7.4.3.4 through 7.4.3.48, and Liferay DXP 7.4 before update 49 does properly isolate objects in difference virtual instances, which allows remote authenticated users in one virtual instance to view objects in a different virtual instance via OAuth 2 scope administration page.
AnalizadaAlta (8.1)0.55%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
SQL injection vulnerability in the upgrade process for SQL Server in Liferay Portal 7.3.1 through 7.4.3.17, and Liferay DXP 7.3 before update 6, and 7.4 before update 18 allows attackers to execute arbitrary SQL commands via the name of a database table's primary key index. This vulnerability is only exploitable when…
AnalizadaMedia (6.1)0.53%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in Layout module in Liferay Portal 7.3.4 through 7.4.3.68, and Liferay DXP 7.3 before update 24, and 7.4 before update 69 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a container type layout fragment's `URL` text field.
AnalizadaMedia (5.4)0.45%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in the Account module in Liferay Portal 7.4.3.21 through 7.4.3.62, and Liferay DXP 7.4 update 21 through 62 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a user's (1) First Name, (2) Middle Name, (3) Last Name, or (4) Job…
AnalizadaMedia (5.4)0.53%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in the Web Content Display widget's article selector in Liferay Liferay Portal 7.4.3.50, and Liferay DXP 7.4 update 50 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a web content article's `Title` field.
AnalizadaMedia (6.1)0.46%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Plugin for OAuth 2.0 module's OAuth2ProviderApplicationRedirect class in Liferay Portal 7.4.3.41 through 7.4.3.52, and Liferay DXP 7.4 update 41 through 52 allow remote attackers to inject arbitrary web script or HTML via the (1) code, or (2) error parameter.
AnalizadaMedia (5.4)0.53%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
AnalizadaMedia (5.4)0.52%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in the Modified Facet widget in Liferay Portal 7.1.0 through 7.4.3.12, and Liferay DXP 7.1 before fix pack 27, 7.2 before fix pack 18, 7.3 before update 4, and 7.4 before update 9 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into…
AnalizadaMedia (6.1)0.52%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Cross-site scripting (XSS) vulnerability in the App Builder module's custom object details page in Liferay Portal 7.3.0 through 7.4.0, and Liferay DXP 7.3 before update 14 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an App Builder custom object's `Name` field.
AnalizadaMedia (5.4)0.45%—Liferay Digital Experience PlatformLiferay Portal24/5/202317/6/2026
Stored cross-site scripting (XSS) vulnerability in Form widget configuration in Liferay Portal 7.1.0 through 7.3.0, and Liferay DXP 7.1 before fix pack 18, and 7.2 before fix pack 5 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a form's `name` field.
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack
Orbitaley — Vulnerabilidades