Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.48% | — | Caxperts UpvwebservicesAICaxperts Udith PortalAI | 8/7/2026 | 9/7/2026 | In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license. | |
| Pendiente de análisis | Alta (8.8) | 0.18% | — | OpenjdkAIUbuntuAIMailcapAIFreedesktop Xdg-desktop-portal-gtkAI | 8/7/2026 | 14/7/2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk… | |
| Analizada | Crítica (9.8) | 0.47% | — | Esri Portal FOR Arcgis | 7/7/2026 | 9/7/2026 | A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with… | |
| Modificada | Crítica (9.8) | 0.85% | — | Esri Portal FOR Arcgis | 7/7/2026 | 29/9/2026 | Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. The following versions are known to be affected: Portal for ArcGIS 12.1 and earlier. Other… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Online JOB PortalAI | 4/7/2026 | 6/7/2026 | A vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |
| Aplazada | Alta (8.5) | 0.36% | — | Wpjobportal WP JOB PortalAI | 26/6/2026 | 26/6/2026 | Contributor SQL Injection in WP Job Portal <= 2.5.2 versions. | |
| Analizada | Alta (7.1) | 0.40% | — | Cmsjunkie J-cruiseportal | 19/6/2026 | 19/8/2026 | Joomla J-CruisePortal 6.0.4 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the guest_adult parameter. Attackers can send POST requests to the cruises endpoint with crafted SQL payloads in the guest_adult parameter to… | |
| Aplazada | Media (6.5) | 0.44% | — | Control Panel Client Portal PROAI | 17/6/2026 | 17/6/2026 | CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Isupplier Portal | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful… | |
| Analizada | Alta (8) | 0.18% | — | Oracle Isupplier Portal | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle iSupplier Portal. Successful attacks… | |
| Modificada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Webcenter Portal | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Webcenter Portal | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 23/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While… | |
| Analizada | Crítica (10) | 0.51% | — | Oracle Webcenter Portal | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Webcenter Portal | 17/6/2026 | 19/6/2026 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the… | |
| Aplazada | Media (6.5) | 0.22% | — | Wpjobportal WP JOB PortalAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in WP Job Portal <= 2.5.2 versions. | |
| Analizada | Media (4.7) | 0.33% | — | Aqara Developer Portal | 12/6/2026 | 9/7/2026 | The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara.com) exhibit cross-origin request sharing, which is an instance of "CWE-942: Permissive Cross-domain Policy with Untrusted Domains," and has an estimated CVSS of… | |
| Analizada | Media (5.3) | 0.38% | — | Aqara Cloud Developer Portal | 12/6/2026 | 10/7/2026 | The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the attacker. This is an instance of "CWE-306: Missing Authentication for Critical Function" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5 Medium). When combined with… | |
| Analizada | Media (6.5) | 0.34% | — | Fortinet Fortiportal | 9/6/2026 | 23/7/2026 | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here> | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpjobportal WP JOB PortalAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Portal allows Reflected XSS. This issue affects WP Job Portal: from n/a through 2.5.1. |