Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
8642 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 1/11/2025 | 17/6/2026 | Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions does not check permission of images in a blog entry, which allows remote attackers to view the images in… | |
| Analizada | Media (4.6) | 0.13% | — | Liferay Digital Experience PlatformLiferay Portal | 1/11/2025 | 17/6/2026 | The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect cache-control header, which allows local… | |
| Analizada | Media (6.5) | 0.27% | — | Summerpearlgroup Vacation Rental Management Platform | 31/10/2025 | 17/6/2026 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password. | |
| Analizada | Media (6.3) | 0.20% | — | Summerpearlgroup Vacation Rental Management Platform | 31/10/2025 | 17/6/2026 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorization. Authenticated attackers can call several endpoints and perform create/update/delete actions on resources owned by arbitrary users by manipulating request parameters (e.g., owner or resource id). | |
| Analizada | Alta (7.5) | 0.40% | — | Summerpearlgroup Vacation Rental Management Platform | 31/10/2025 | 17/6/2026 | Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Service (DoS) condition in the HTTP connection handling layer, where an attacker that opens and maintains many slow or partially-completed HTTP connections can exhaust the server’s connection pool and… | |
| Analizada | Media (4.6) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 31/10/2025 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.4.3.35 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 35 through update 92 allow remote attackers to inject arbitrary web script or HTML via… | |
| Analizada | Media (5.1) | 0.24% | — | Liferay Digital Experience PlatformLiferay Portal | 31/10/2025 | 17/6/2026 | Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 4 through update 92 allows remote attackers to inject arbitrary web script or HTML via the… | |
| Analizada | Alta (7.8) | 0.14% | — | IBM Infosphere Information Server | 31/10/2025 | 7/10/2026 | IBM InfoSphere Information Server 11.7.0.0 hasta 11.7.1.6 podría permitir a un usuario no-root obtener privilegios/capacidades más altos dentro del ámbito de un contenedor debido a la ejecución con privilegios innecesarios. | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 30/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, 7.3 GA through update 36, and older unsupported versions allows remote attackers… | |
| Analizada | Media (5.1) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 30/10/2025 | 17/6/2026 | By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions is vulnerable to DNS rebinding attacks, which allows remote attackers to… | |
| Analizada | Media (6.3) | 0.39% | — | Liferay Digital Experience PlatformLiferay Portal | 30/10/2025 | 17/6/2026 | Password enumeration vulnerability in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 2024.Q1.5, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to determine a user’s… | |
| Aplazada | Media (5) | 0.22% | — | Inforcer PlatformAI | 29/10/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low privileges to enumerate and access tenant information belonging to other clients via modification of the tenant ID in the request URL. | |
| Analizada | Media (4.9) | 0.30% | — | I13websolution Easy Testimonial Slider AND Form | 29/10/2025 | 17/6/2026 | The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Aplazada | Media (6.5) | 0.22% | — | Doppler FormsAI | 29/10/2025 | 8/10/2026 | El plugin de WordPress Doppler Forms hasta la versión 2.5.1 registra una acción AJAX install_extension sin verificar las capacidades del usuario ni utilizar un nonce. Como resultado, cualquier usuario autenticado -incluidos aquellos con el rol de Suscriptor- puede instalar y activar un plugin de WordPress Doppler… | |
| Analizada | Media (6.9) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.109, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has verified their email address, which allows remote users to access and… | |
| Analizada | Alta (7) | 0.18% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | CSRF vulnerability in Headless API in Liferay Portal 7.4.0 through 7.4.3.107, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to execute any Headless API via the `endpoint` parameter. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1 y 5.1 podría permitir a un usuario autenticado provocar el bloqueo del programa debido a una escritura fuera de límites. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1 y 5.1 podría permitir a un usuario autenticado provocar que el programa falle debido al cálculo incorrecto del tamaño de los datos a los que se está apuntando. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1 y 5.1 podría permitir a un usuario autenticado provocar que el programa falle debido a la sobrescritura de un búfer cuando se asigna en la pila. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 8/10/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, y 5.1 podrían permitir a un usuario… | |
| Analizada | Media (6.9) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access to the database to obtain the token,… | |
| Analizada | Alta (7.1) | 0.39% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.99, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not limit the number of objects returned from Headless API requests, which allows remote attackers to perform denial-of-service (DoS) attacks on… | |
| Analizada | Media (4.6) | 0.14% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | Information exposure through log file vulnerability in LDAP import feature in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows local users to view user email… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.7 through 7.4.3.103, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 service pack 3 through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an Account Role’s… | |
| Analizada | Media (6.9) | 0.25% | — | Liferay Digital Experience PlatformLiferay Portal | 27/10/2025 | 17/6/2026 | Open redirect vulnerability in page administration in Liferay Portal 7.4.0 through 7.4.3.97, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary… |