Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
8646 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.5) | 0.19% | — | Brainstormforce SureformsAI | 23/9/2025 | 17/6/2026 | The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks. | |
| Aplazada | Media (4.3) | 0.22% | — | SAP BI PlatformAI | 23/9/2025 | 17/6/2026 | SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system. | |
| Analizada | Baja (2.1) | 0.35% | — | Fuyang Lipengjun Platform | 23/9/2025 | 17/6/2026 | A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the file /sys/smslog/queryAll. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.35% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a… | |
| Analizada | Media (5.3) | 0.27% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to add a note to an order in… | |
| Analizada | Baja (2.1) | 0.35% | — | Fuyang Lipengjun Platform | 22/9/2025 | 17/6/2026 | A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of the file /topiccategory/queryAll. This manipulation causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 22/9/2025 | 17/6/2026 | A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /topic/queryAll. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is now public and may be used. | |
| Analizada | Media (5.3) | 0.25% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 22/9/2025 | 30/9/2026 | Una vulnerabilidad de seguridad ha sido detectada en la plataforma fuyang_lipengjun 1.0. Este problema afecta la función UserCouponController del archivo /usercoupon/queryAll. La manipulación conduce a una autorización indebida. La explotación remota del ataque es posible. El exploit ha sido divulgado públicamente y… | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci Shortcodes AND PerformanceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through < 6.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Fatcatapps Getresponse FormsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps GetResponse Forms getresponse allows Stored XSS.This issue affects GetResponse Forms: from n/a through <= 2.6.0. | |
| Aplazada | Media (4.3) | 0.25% | — | Vikasratudi VpsuformAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Vikas Ratudi VPSUForm v-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VPSUForm: from n/a through <= 3.2.20. | |
| Aplazada | Media (4.7) | 0.28% | — | Crmperks WP Gravity Forms Keap InfusionsoftAI | 22/9/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Phishing.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.6. | |
| Aplazada | Media (4.3) | 0.29% | — | Nurul Amin WP System InformationAI | 22/9/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Nurul Amin WP System Information wp-system-info allows Retrieve Embedded Sensitive Data.This issue affects WP System Information: from n/a through <= 1.5. | |
| Aplazada | Media (5.9) | 0.22% | — | Tmontg1 Form Generator FOR WordpressAIJotformAI | 22/9/2025 | 30/9/2026 | Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en tmontg1 Form Generator para WordPress permite XSS Almacenado. Este problema afecta a Form Generator para WordPress: desde n/a hasta 1.5.2. | |
| Analizada | Media (4.8) | 0.21% | — | Liferay Digital Experience PlatformLiferay Portal | 22/9/2025 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected… | |
| Aplazada | Media (4.3) | 0.16% | — | Piotnet FormsAI | 22/9/2025 | 30/9/2026 | Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en piotnetdotcom Piotnet Forms permite la falsificación de petición en sitios cruzados. Este problema afecta a Piotnet Forms: desde n/a hasta 1.0.30. | |
| Aplazada | Alta (8.8) | 0.29% | — | Boodskap IOT PlatformAI | 22/9/2025 | 17/6/2026 | Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department | |
| Aplazada | Crítica (9.8) | 0.53% | — | Aikaan IOT Management PlatformAI | 22/9/2025 | 17/6/2026 | Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot into other connected IoT devices. This can lead to remote code… | |
| Aplazada | Media (5.4) | 0.31% | — | Horato Internet Technologies Ind. AND Trade INC Virtual Library PlatformAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Internet Technologies Ind. And Trade Inc. Virtual Library Platform allows Reflected XSS. This issue affects Virtual Library Platform: before v202. | |
| Aplazada | Alta (7.1) | 0.38% | — | Sitecore Experience ManagerAISitecore Experience PlatformAI | 21/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform… | |
| Aplazada | Media (4.3) | 0.20% | — | Brainstormforce SureformsAI | 20/9/2025 | 17/6/2026 | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for… | |
| Analizada | Media (6.9) | 0.37% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote… | |
| Analizada | Media (5.1) | 0.18% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions allows remote attackers… | |
| Analizada | Media (6.9) | 0.28% | — | Liferay Digital Experience PlatformLiferay Portal | 19/9/2025 | 17/6/2026 | Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to… |