Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
8646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.9) | 0.29% | — | Jhumanj Opnform | 8/10/2025 | 8/10/2026 | Se ha encontrado una vulnerabilidad en JhumanJ OpnForm hasta la versión 1.9.3. Esto afecta a una parte desconocida del archivo /api/open/forms/ del componente Editor de Formularios. Esta manipulación provoca cross-site scripting. El ataque puede iniciarse de forma remota. El exploit ha sido publicado y puede usarse.… | |
| Analizada | Baja (2.1) | 0.38% | — | Jhumanj Opnform | 8/10/2025 | 8/10/2026 | Una vulnerabilidad fue detectada en JhumanJ OpnForm hasta 1.9.3. Afectada por este problema es alguna funcionalidad desconocida del archivo /answer. La manipulación resulta en carga sin restricciones. El ataque puede ser lanzado remotamente. El exploit es ahora público y puede ser usado. El parche se identifica como… | |
| Analizada | Baja (2.1) | 0.40% | — | Jhumanj Opnform | 8/10/2025 | 8/10/2026 | Una vulnerabilidad de seguridad ha sido detectada en JhumanJ OpnForm hasta 1.9.3. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /show/submissions. La manipulación conduce a cross-site scripting. El ataque puede ser iniciado remotamente. El exploit ha sido divulgado públicamente y puede… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 7/10/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.15 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, and 7.4 update 15 through update 92 allow remote attackers to inject arbitrary web script or HTML via crafted payload injected into a Terms… | |
| Analizada | Media (4.8) | 0.22% | — | Liferay Digital Experience PlatformLiferay Portal | 7/10/2025 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Commerce Search Result widget in Liferay Portal 7.4.0 through 7.4.3.111, and Liferay DXP 2023.Q4 before patch 6, 2023.Q3 before patch 9, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a… | |
| Analizada | Media (4.8) | 0.23% | — | Liferay Digital Experience PlatformLiferay Portal | 6/10/2025 | 17/6/2026 | The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a user’s name in the “Content-Disposition” header, which allows remote authenticated… | |
| Analizada | Crítica (9.8) | 0.68% | — | IBM Transformation Extender Advanced | 6/10/2025 | 17/6/2026 | IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system. | |
| Aplazada | Crítica (9.3) | 2.4% | 💥 Exploit | Xwiki PlatformAI | 6/10/2025 | 9/10/2026 | XWiki Platform es una plataforma wiki genérica que ofrece servicios en tiempo de ejecución para aplicaciones construidas sobre ella. A partir de la versión 4.3-milestone-1 y antes de las versiones 16.10.9, 17.4.2 y 17.5.0, la URL de búsqueda REST es vulnerable a la inyección HQL a través del parámetro 'orderField'. El… | |
| Aplazada | Media (5.5) | 0.69% | — | Four-faith Water Conservancy Informatization PlatformAI | 6/10/2025 | 9/10/2026 | Se detectó una vulnerabilidad en la Plataforma de Informatización de Conservación de Agua Four-Faith hasta 2.2. Esto afecta una parte desconocida del archivo /aloneReport/index.do/.. / ../aloneReport/download.do;othersusrlogout.do. Realizar la manipulación del argumento fileName resulta en un salto de ruta. Es posible… | |
| Aplazada | Media (5.5) | 0.69% | — | Four-faith Water Conservancy Informatization PlatformAI | 6/10/2025 | 9/10/2026 | Se ha detectado una vulnerabilidad de seguridad en la Plataforma de Informatización de Conservación de Agua Four-Faith hasta la versión 2.2. Este problema afecta a alguna funcionalidad desconocida del archivo /stAlarmConfigure/index.do/.. / ../aloneReport/download.do;otherlogout.do. Dicha manipulación del argumento… | |
| Analizada | Media (4.6) | 0.30% | — | Liferay Digital Experience PlatformLiferay Portal | 3/10/2025 | 17/6/2026 | A vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.4, 2024.Q4.0 through 2024.Q4.5, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows… | |
| Aplazada | Media (4.3) | 0.15% | — | Paypal FormsAI | 3/10/2025 | 8/10/2026 | El plugin PayPal Forms para WordPress es vulnerable a la falsificación de petición en sitios cruzados en todas las versiones hasta e incluyendo la 1.0.3. Esto se debe a la falta de validación de nonce en las funciones de creación y gestión de formularios. Esto hace posible que atacantes no autenticados creen nuevos… | |
| Aplazada | Media (4.1) | 0.21% | — | Isin Basi Advertisement Information Technologies Trade INC WorkifAI | 3/10/2025 | 8/10/2026 | Vulnerabilidad de Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web (XSS o 'cross-site scripting') en el Workif de IT de Isin Basi Advertisement Information Technologies Trade Inc. permite cross-site scripting (XSS). Este problema afecta al Workif de IT: hasta el 20251003. | |
| Aplazada | Crítica (9.3) | 0.46% | — | Risc Zero Risc0 Zkvm PlatformAIRisc Zero Risc0 AggregationAIRisc Zero Risc0 Zkos V1compatAIRisc Zero Risc0 ZkvmAI | 2/10/2025 | 17/6/2026 | RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a crafted response to write to an arbitrary memory location in the guest. This… | |
| Aplazada | Alta (8.8) | 0.34% | — | Kissflow Work PlatformAI | 1/10/2025 | 5/7/2026 | A stored cross-site scripting (XSS) in Kissflow Work Platform Kissflow Application Versions 7337 Account v2.0 to v4.2vallows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Alta (8.8) | 0.47% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, an unauthenticated attacker could trigger a blind server-side request forgery (SSRF) potentially letting an attacker perform REST API calls on behalf of an… | |
| Analizada | Media (4.9) | 0.56% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a user who holds a role that contains the high-privilege capability `change_authentication`, could send multiple LDAP bind requests to a specific internal endpoint,… | |
| Analizada | Media (6.5) | 0.30% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the… | |
| Analizada | Media (5.4) | 0.36% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved… | |
| Analizada | Media (5.4) | 0.36% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the… | |
| Analizada | Media (6.5) | 0.44% | — | SplunkSplunk Cloud Platform | 1/10/2025 | 17/6/2026 | In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in… | |
| Analizada | Media (6.2) | 0.11% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 could allow a local user to perform unauthorized actions due to improper access controls. | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Analizada | Alta (8.8) | 0.22% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Media (4.4) | 0.12% | — | IBM Transformation Extender Advanced | 1/10/2025 | 17/6/2026 | IBM Transformation Extender Advanced 10.0.1 stores potentially sensitive information in log files that could be read by a local user. |