Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

3955 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.6)0.22%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.
AnalizadaMedia (4.6)0.21%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows…
AnalizadaMedia (5.1)0.24%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes "Internal Server Error" in the response body when a login attempt is made…
AnalizadaMedia (4.8)0.23%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated…
AplazadaMedia (6.1)0.22%—SAP Netweaver Abap PlatformAI9/9/202517/6/2026
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the…
AnalizadaMedia (4.8)0.20%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to…
AnalizadaBaja (2.1)0.33%—Fuyang Lipengjun Platform8/9/202517/6/2026
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public…
AplazadaMedia (6.5)0.17%—Course Finder Course Booking PlatformAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform4/9/202517/6/2026
A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
AnalizadaCrítica (9)51%⚠ Explotación activa💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
AnalizadaAlta (7.5)6.5%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
AnalizadaCrítica (9.8)19%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform…
AnalizadaAlta (8.8)1.6%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
AnalizadaAlta (8.8)8.6%—Openagentplatform Dive3/9/202517/6/2026
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code Execution vulnerability triggered through a custom url value, `transport` in the JSON object. An attacker can exploit the vulnerability in the…
ModificadaAlta (7.5)2.3%💥 PoCRedhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+42/9/20256/10/2026
Se encontró una vulnerabilidad en Undertow donde solicitudes de cliente malformadas pueden desencadenar restablecimientos de flujo del lado del servidor sin activar contadores de abuso. Este problema, conocido como el ataque “MadeYouReset”, permite a clientes maliciosos inducir una carga de trabajo excesiva del…
AnalizadaAlta (7.5)0.42%—Liferay Digital Experience PlatformLiferay Portal1/9/202517/6/2026
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin…
AnalizadaMedia (4.6)0.29%—Liferay Digital Experience PlatformLiferay Portal29/8/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the…
AplazadaBaja (2)0.26%—Weaver E-mobile Mobile Management PlatformAI28/8/202525/9/2026
Se identificó una vulnerabilidad en la Plataforma de Gestión Móvil Weaver E-Mobile hasta el 20250813. Una funcionalidad desconocida se ve afectada por esta vulnerabilidad. La manipulación del argumento gohome conduce a Cross-Site Scripting. El ataque puede iniciarse de forma remota. El exploit está disponible…
AplazadaCrítica (10)0.81%—Dahua Smart Park Integrated Management PlatformAI27/8/20253/9/2026
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to upload arbitrary files to the server via…
AnalizadaMedia (6.8)0.44%—Liferay Digital Experience PlatformLiferay Portal23/8/202517/6/2026
Liferay Portal 7.4.0 a 7.3.3.131, y Liferay DXP 2024.Q4.0, 2024.Q3.1 a 2024.Q3.13, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.12 y 7.4 GA hasta la actualización 92 permiten la carga de archivos sin restricciones en el componente de libros de estilo que se procesan dentro del entorno, lo que permite la ejecución de…
AnalizadaMedia (6.9)0.19%—Liferay Digital Experience PlatformLiferay Portal23/8/202517/6/2026
Una vulnerabilidad de cross-site scripting almacenados en Liferay Portal 7.4.0 a 7.4.3.131, y Liferay DXP 2024.Q4.0, 2024.Q3.1 a 2024.Q3.13, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.13 y 7.4 GA hasta la actualización 92 permite a un atacante remoto no autenticado inyectar JavaScript en el campo de texto de un…
AnalizadaMedia (6.9)0.31%—Liferay Digital Experience PlatformLiferay Portal23/8/202517/6/2026
Existe Self-ReDoS (denegación de servicio por expresión regular) con el campo de búsqueda de nombre de rol del portlet JavaScript de Kaleo Designer en Liferay Portal 7.4.0 a 7.4.3.131, y Liferay DXP 2024.Q4.0 a 2024.Q4.1, 2024.Q3.0 a 2024.Q3.13, 2024.Q2.1 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.20 y 7.4 GA hasta la…
AnalizadaMedia (5.1)0.18%—Liferay Digital Experience PlatformLiferay Portal23/8/202517/6/2026
La vulnerabilidad de redirección abierta en el parámetro /c/portal/edit_info_item en Liferay Portal 7.4.3.86 a 7.4.3.131, y Liferay DXP 2024.Q3.1 a 2024.Q3.9, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.12 y 7.4 actualización 86 a 92 permite a un atacante explotar esta vulnerabilidad de seguridad para redirigir a los…
AnalizadaMedia (4.6)0.23%—Liferay Digital Experience PlatformLiferay Portal23/8/202517/6/2026
La vulnerabilidad de cross-site scripting (XSS) almacenado en Liferay Portal 7.4.0 a 7.4.3.131, y Liferay DXP 2024.Q3.1 a 2024.Q3.8, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.12 y 7.4 GA hasta la actualización 92 permite a atacantes remotos ejecutar scripts web o HTML arbitrarios a través de la pestaña de…
AnalizadaMedia (5.1)0.32%—Liferay Digital Experience PlatformLiferay Portal23/8/202517/6/2026
Liferay Portal 7.4.0 a 7.4.3.131, y Liferay DXP 2024.Q4.0 a 2024.Q4.7, 2024.Q3.1 a 2024.Q3.13, 2024.Q2.0 a 2024.Q2.13, 2024.Q1.1 a 2024.Q1.15 y 7.4 GA hasta la actualización 92 permiten a los usuarios autenticados sin ningún permiso acceder a información confidencial de usuarios administradores mediante las API JSONWS.