Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.48%—Caxperts UpvwebservicesAICaxperts Udith PortalAI8/7/20269/7/2026
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
Pendiente de análisisAlta (8.8)0.18%—OpenjdkAIUbuntuAIMailcapAIFreedesktop Xdg-desktop-portal-gtkAI8/7/202614/7/2026
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk…
AnalizadaCrítica (9.8)0.47%—Esri Portal FOR Arcgis7/7/20269/7/2026
A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with…
ModificadaCrítica (9.8)0.85%—Esri Portal FOR Arcgis7/7/202629/9/2026
Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other…
AplazadaMedia (5.5)0.43%—Code-projects Online JOB PortalAI4/7/20266/7/2026
A vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
AplazadaAlta (8.5)0.36%—Wpjobportal WP JOB PortalAI26/6/202626/6/2026
Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
AnalizadaAlta (7.1)0.40%—Cmsjunkie J-cruiseportal19/6/202619/8/2026
Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to…
AplazadaMedia (6.5)0.44%—Control Panel Client Portal PROAI17/6/202617/6/2026
CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions.
AnalizadaAlta (7.5)0.33%—Oracle Isupplier Portal17/6/202618/6/2026
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful…
AnalizadaAlta (8)0.18%—Oracle Isupplier Portal17/6/202618/6/2026
Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle iSupplier Portal. Successful attacks…
ModificadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the…
AnalizadaCrítica (10)0.51%—Oracle Webcenter Portal17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.…
AnalizadaCrítica (9.8)0.51%—Oracle Webcenter Portal17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Portal.…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal.…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202623/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal.…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202618/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While…
AnalizadaCrítica (10)0.51%—Oracle Webcenter Portal17/6/202619/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202619/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202619/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the…
AnalizadaCrítica (9.9)0.43%—Oracle Webcenter Portal17/6/202619/6/2026
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the…
AplazadaMedia (6.5)0.22%—Wpjobportal WP JOB PortalAI15/6/202617/6/2026
Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions.
AnalizadaMedia (4.7)0.33%—Aqara Developer Portal12/6/20269/7/2026
The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of…
AnalizadaMedia (5.3)0.38%—Aqara Cloud Developer Portal12/6/202610/7/2026
The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with…
AnalizadaMedia (6.5)0.34%—Fortinet Fortiportal9/6/202623/7/2026
A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>
AplazadaAlta (7.1)0.25%—Wpjobportal WP JOB PortalAI2/6/202622/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1.