Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack
ModificadaMedia (5.4)0.44%—Esri Portal FOR Arcgis10/5/202317/6/2026
There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered).
ModificadaAlta (8.8)0.27%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions.
AnalizadaMedia (6.1)0.54%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
AnalizadaMedia (6.1)0.50%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser.
AnalizadaMedia (6.1)0.49%—Esri Portal FOR Arcgis9/5/202317/6/2026
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
ModificadaMedia (5.4)0.32%—Esri Portal FOR Arcgis9/5/202317/6/2026
Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access.
ModificadaCrítica (9.8)12%💥 ExploitLiferay Portal16/4/202317/6/2026
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file.
ModificadaMedia (6.5)0.54%—Jenkins Report Portal12/4/202317/6/2026
A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified bearer token authentication.
ModificadaAlta (8.8)0.78%—Jenkins Report Portal12/4/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified bearer token authentication.
ModificadaMedia (4.3)0.43%—Jenkins Report Portal12/4/202317/6/2026
Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them.
ModificadaMedia (4.3)0.32%—Jenkins Report Portal12/4/202317/6/2026
Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.
ModificadaAlta (7.8)0.25%—Siemens TIA Portal11/4/202317/6/2026
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal…
ModificadaMedia (6.5)0.38%—SAP Netweaver Enterprise Portal11/4/202317/6/2026
In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and integrity.
ModificadaCrítica (9.8)0.81%—Mayurik Best Online News Portal9/4/202317/6/2026
A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be…
ModificadaCrítica (9.8)0.94%—Hgiga Oaklouds Portal27/3/202317/6/2026
HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service.
ModificadaAlta (8.8)0.26%—Cozmoslabs Client Portal15/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions.
ModificadaMedia (4.9)0.52%—SAP Netweaver Enterprise Portal14/3/202317/6/2026
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which…
ModificadaMedia (6.5)0.47%—Fortinet FortianalyzerFortinet FortimanagerFortinet FortiportalFortinet Fortiswitch7/3/202317/6/2026
A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10,…
ModificadaMedia (6.5)0.69%—Fortinet Fortiportal16/2/202317/6/2026
An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.
ModificadaBaja (3.7)0.85%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be…
ModificadaCrítica (9.8)0.81%—Mayurik Best Online News Portal12/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
ModificadaMedia (4.3)0.73%—Mojoportal9/2/202317/6/2026
An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx
ModificadaMedia (5.3)0.70%—Mojoportal9/2/202317/6/2026
An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled.
Orbitaley — Vulnerabilidades