Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

8646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.9)0.29%—Jhumanj Opnform8/10/20258/10/2026
Se ha encontrado una vulnerabilidad en JhumanJ OpnForm hasta la versión 1.9.3. Esto afecta a una parte desconocida del archivo /api/open/forms/ del componente Editor de Formularios. Esta manipulación provoca cross-site scripting. El ataque puede iniciarse de forma remota. El exploit ha sido publicado y puede usarse.…
AnalizadaBaja (2.1)0.38%—Jhumanj Opnform8/10/20258/10/2026
Una vulnerabilidad fue detectada en JhumanJ OpnForm hasta 1.9.3. Afectada por este problema es alguna funcionalidad desconocida del archivo /answer. La manipulación resulta en carga sin restricciones. El ataque puede ser lanzado remotamente. El exploit es ahora público y puede ser usado. El parche se identifica como…
AnalizadaBaja (2.1)0.40%—Jhumanj Opnform8/10/20258/10/2026
Una vulnerabilidad de seguridad ha sido detectada en JhumanJ OpnForm hasta 1.9.3. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /show/submissions. La manipulación conduce a cross-site scripting. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado públicamente y puede…
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal7/10/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms…
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal7/10/202517/6/2026
Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a…
AnalizadaMedia (4.8)0.23%—Liferay Digital Experience PlatformLiferay Portal6/10/202517/6/2026
The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated…
AnalizadaCrítica (9.8)0.68%—IBM Transformation Extender Advanced6/10/202517/6/2026
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
AplazadaCrítica (9.3)2.4%💥 ExploitXwiki PlatformAI6/10/20259/10/2026
XWiki Platform es una plataforma wiki genérica que ofrece servicios en tiempo de ejecución para aplicaciones construidas sobre ella. A partir de la versión 4.3-milestone-1 y antes de las versiones 16.10.9, 17.4.2 y 17.5.0, la URL de búsqueda REST es vulnerable a la inyección HQL a través del parámetro 'orderField'. El…
AplazadaMedia (5.5)0.69%—Four-faith Water Conservancy Informatization PlatformAI6/10/20259/10/2026
Se detectó una vulnerabilidad en la Plataforma de Informatización de Conservación de Agua Four-Faith hasta 2.2. Esto afecta una parte desconocida del archivo /aloneReport/index.do/.. / ../aloneReport/download.do;othersusrlogout.do. Realizar la manipulación del argumento fileName resulta en un salto de ruta. Es posible…
AplazadaMedia (5.5)0.69%—Four-faith Water Conservancy Informatization PlatformAI6/10/20259/10/2026
Se ha detectado una vulnerabilidad de seguridad en la Plataforma de Informatización de Conservación de Agua Four-Faith hasta la versión 2.2. Este problema afecta a alguna funcionalidad desconocida del archivo /stAlarmConfigure/index.do/.. / ../aloneReport/download.do;otherlogout.do. Dicha manipulación del argumento…
AnalizadaMedia (4.6)0.30%—Liferay Digital Experience PlatformLiferay Portal3/10/202517/6/2026
A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows…
AplazadaMedia (4.3)0.15%—Paypal FormsAI3/10/20258/10/2026
El plugin PayPal Forms para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta e incluyendo la 1.0.3. Esto se debe a la falta de validación de nonce en las funciones de creación y gestión de formularios. Esto hace posible que atacantes no autenticados creen nuevos…
AplazadaMedia (4.1)0.21%—Isin Basi Advertisement Information Technologies Trade INC WorkifAI3/10/20258/10/2026
Vulnerabilidad de Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web (XSS o 'cross-site scripting') en el Workif de IT de Isin Basi Advertisement Information Technologies Trade Inc. permite cross-site scripting (XSS). Este problema afecta al Workif de IT: hasta el 20251003.
AplazadaCrítica (9.3)0.46%—Risc Zero Risc0 Zkvm PlatformAIRisc Zero Risc0 AggregationAIRisc Zero Risc0 Zkos V1compatAIRisc Zero Risc0 ZkvmAI2/10/202517/6/2026
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This…
AplazadaAlta (8.8)0.34%—Kissflow Work PlatformAI1/10/20255/7/2026
A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaAlta (8.8)0.47%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an…
AnalizadaMedia (4.9)0.56%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint,…
AnalizadaMedia (6.5)0.30%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the…
AnalizadaMedia (5.4)0.36%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved…
AnalizadaMedia (5.4)0.36%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the…
AnalizadaMedia (6.5)0.44%—SplunkSplunk Cloud Platform1/10/202517/6/2026
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in…
AnalizadaMedia (6.2)0.11%—IBM Transformation Extender Advanced1/10/202517/6/2026
IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls.
AnalizadaAlta (7.5)0.27%—IBM Transformation Extender Advanced1/10/202517/6/2026
IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
AnalizadaAlta (8.8)0.22%—IBM Transformation Extender Advanced1/10/202517/6/2026
IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
AnalizadaMedia (4.4)0.12%—IBM Transformation Extender Advanced1/10/202517/6/2026
IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user.