Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack | |
| Modificada | Media (5.4) | 0.44% | — | Esri Portal FOR Arcgis | 10/5/2023 | 17/6/2026 | There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 11.0 and below that may allow a remote, authenticated attacker to create a crafted link which when clicked could render arbitrary HTML in the victim’s browser (no stateful change made or customer data rendered). | |
| Modificada | Alta (8.8) | 0.27% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is a cross-site-request forgery vulnerability in Esri Portal for ArcGIS Versions 11.0 and below that may allow an attacker to trick an authorized user into executing unwanted actions. | |
| Analizada | Media (6.1) | 0.54% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and below which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | |
| Analizada | Media (6.1) | 0.50% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1and before which may allow a remote, unauthenticated attacker to create a crafted link which when clicked could potentially execute arbitrary JavaScript code in the victim’s browser. | |
| Analizada | Media (6.1) | 0.49% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks. | |
| Modificada | Media (5.4) | 0.32% | — | Esri Portal FOR Arcgis | 9/5/2023 | 17/6/2026 | Changes to user permissions in Portal for ArcGIS 10.9.1 and below are incompletely applied in specific use cases. This issue may allow users to access content that they are no longer privileged to access. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Liferay Portal | 16/4/2023 | 17/6/2026 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not demonstrate how an unauthorized user can upload a file. | |
| Modificada | Media (6.5) | 0.54% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins Report Portal Plugin 0.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified bearer token authentication. | |
| Modificada | Alta (8.8) | 0.78% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Report Portal Plugin 0.5 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified bearer token authentication. | |
| Modificada | Media (4.3) | 0.43% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Report Portal | 12/4/2023 | 17/6/2026 | Jenkins Report Portal Plugin 0.5 and earlier stores ReportPortal access tokens unencrypted in job config.xml files on the Jenkins controller as part of its configuration where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Modificada | Alta (7.8) | 0.25% | — | Siemens TIA Portal | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Integrated Automation Portal (TIA Portal) V16 (All versions < V16 Update 7), Totally Integrated Automation Portal (TIA Portal) V17 (All versions < V17 Update 6), Totally Integrated Automation Portal… | |
| Modificada | Media (6.5) | 0.38% | — | SAP Netweaver Enterprise Portal | 11/4/2023 | 17/6/2026 | In SAP NetWeaver Enterprise Portal - version 7.50, an unauthenticated attacker can attach to an open interface and make use of an open API to access a service which will enable them to access or modify server settings and data, leading to limited impact on confidentiality and integrity. | |
| Modificada | Crítica (9.8) | 0.81% | — | Mayurik Best Online News Portal | 9/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be… | |
| Modificada | Crítica (9.8) | 0.94% | — | Hgiga Oaklouds Portal | 27/3/2023 | 17/6/2026 | HGiga OAKlouds file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker can exploit this vulnerability to upload and run arbitrary executable files to perform arbitrary command or disrupt service. | |
| Modificada | Alta (8.8) | 0.26% | — | Cozmoslabs Client Portal | 15/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Madalin Ungureanu, Antohe Cristian Client Portal – Private user pages and login plugin <= 1.1.8 versions. | |
| Modificada | Media (4.9) | 0.52% | — | SAP Netweaver Enterprise Portal | 14/3/2023 | 17/6/2026 | SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data. It allows the attacker to view sensitive data which… | |
| Modificada | Media (6.5) | 0.47% | — | Fortinet FortianalyzerFortinet FortimanagerFortinet FortiportalFortinet Fortiswitch | 7/3/2023 | 17/6/2026 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 through 6.0.4, FortiPortal version 6.0.0 through 6.0.9, 5.3.0 through 5.3.8, 5.2.x, 5.1.0, 5.0.x, 4.2.x, 4.1.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10,… | |
| Modificada | Media (6.5) | 0.69% | — | Fortinet Fortiportal | 16/2/2023 | 17/6/2026 | An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page. | |
| Modificada | Baja (3.7) | 0.85% | — | Mayurik Best Online News Portal | 12/2/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure of sensitive information through data queries. The attack can be… | |
| Modificada | Crítica (9.8) | 0.81% | — | Mayurik Best Online News Portal | 12/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. Affected is an unknown function of the component Login Page. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (4.3) | 0.73% | — | Mojoportal | 9/2/2023 | 17/6/2026 | An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx | |
| Modificada | Media (5.3) | 0.70% | — | Mojoportal | 9/2/2023 | 17/6/2026 | An issue in Mojoportal v2.7.0.0 allows an unauthenticated attacker to register a new user even if the Allow User Registrations feature is disabled. |