Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

8646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.5)0.19%—Brainstormforce SureformsAI23/9/202517/6/2026
The SureForms WordPress plugin before 1.9.1 does not sanitise and escape some parameters when outputing them in the page, which could allow admin and above users to perform Cross-Site Scripting attacks.
AplazadaMedia (4.3)0.22%—SAP BI PlatformAI23/9/202517/6/2026
SAP BI Platform allows an attacker to modify the IP address of the LogonToken for the OpenDoc. On accessing the modified link in the browser a different server could get the ping request. This has low impact on integrity with no impact on confidentiality and availability of the system.
AnalizadaBaja (2.1)0.35%—Fuyang Lipengjun Platform23/9/202517/6/2026
A vulnerability has been found in fuyang_lipengjun platform 1.0. The impacted element is the function SysSmsLogController of the file /sys/smslog/queryAll. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (6.9)0.35%—Liferay Digital Experience PlatformLiferay Portal22/9/202517/6/2026
In Liferay Portal 7.4.0 through 7.4.3.112, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions the audit events records a user’s password reminder answer, which allows remote authenticated users to obtain a…
AnalizadaMedia (5.3)0.27%—Liferay Digital Experience PlatformLiferay Portal22/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability with commerce order notes in Liferay Portal 7.3.5 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to add a note to an order in…
AnalizadaBaja (2.1)0.35%—Fuyang Lipengjun Platform22/9/202517/6/2026
A flaw has been found in fuyang_lipengjun platform 1.0. The affected element is the function TopicCategoryController of the file /topiccategory/queryAll. This manipulation causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform22/9/202517/6/2026
A vulnerability was detected in fuyang_lipengjun platform 1.0. Impacted is the function TopicController of the file /topic/queryAll. The manipulation results in improper authorization. The attack can be executed remotely. The exploit is now public and may be used.
AnalizadaMedia (5.3)0.25%—Liferay Digital Experience PlatformLiferay Portal22/9/202517/6/2026
Batch Engine in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 does not properly check permission with import and export tasks, which allows remote authenticated users to access the exported data via the REST APIs.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform22/9/202530/9/2026
Una vulnerabilidad de seguridad ha sido detectada en la plataforma fuyang_lipengjun 1.0. Este problema afecta la función UserCouponController del archivo /usercoupon/queryAll. La manipulación conduce a una autorización indebida. La explotación remota del ataque es posible. El exploit ha sido divulgado públicamente y…
AplazadaMedia (6.5)0.17%—Pencidesign Penci Shortcodes AND PerformanceAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through < 6.1.
AplazadaMedia (6.5)0.20%—Fatcatapps Getresponse FormsAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fatcatapps GetResponse Forms getresponse allows Stored XSS.This issue affects GetResponse Forms: from n/a through <= 2.6.0.
AplazadaMedia (4.3)0.25%—Vikasratudi VpsuformAI22/9/202517/6/2026
Missing Authorization vulnerability in Vikas Ratudi VPSUForm v-form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VPSUForm: from n/a through <= 3.2.20.
AplazadaMedia (4.7)0.28%—Crmperks WP Gravity Forms Keap InfusionsoftAI22/9/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Keap/Infusionsoft gf-infusionsoft allows Phishing.This issue affects WP Gravity Forms Keap/Infusionsoft: from n/a through <= 1.2.6.
AplazadaMedia (4.3)0.29%—Nurul Amin WP System InformationAI22/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Nurul Amin WP System Information wp-system-info allows Retrieve Embedded Sensitive Data.This issue affects WP System Information: from n/a through <= 1.5.
AplazadaMedia (5.9)0.22%—Tmontg1 Form Generator FOR WordpressAIJotformAI22/9/202530/9/2026
Neutralización Incorrecta de Entrada Durante la Generación de Páginas Web ('cross-site scripting') vulnerabilidad en tmontg1 Form Generator para WordPress permite XSS Almacenado. Este problema afecta a Form Generator para WordPress: desde n/a hasta 1.5.2.
AnalizadaMedia (4.8)0.21%—Liferay Digital Experience PlatformLiferay Portal22/9/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in the notifications widget in Liferay Portal 7.4.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected…
AplazadaMedia (4.3)0.16%—Piotnet FormsAI22/9/202530/9/2026
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en piotnetdotcom Piotnet Forms permite la falsificación de petición en sitios cruzados. Este problema afecta a Piotnet Forms: desde n/a hasta 1.0.30.
AplazadaAlta (8.8)0.29%—Boodskap IOT PlatformAI22/9/202517/6/2026
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department
AplazadaCrítica (9.8)0.53%—Aikaan IOT Management PlatformAI22/9/202517/6/2026
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH private key, allows remote attackers to authenticate to the cloud controller, gain interactive shell access, and pivot into other connected IoT devices. This can lead to remote code…
AplazadaMedia (5.4)0.31%—Horato Internet Technologies Ind. AND Trade INC Virtual Library PlatformAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Internet Technologies Ind. And Trade Inc. Virtual Library Platform allows Reflected XSS. This issue affects Virtual Library Platform: before v202.
AplazadaAlta (7.1)0.38%—Sitecore Experience ManagerAISitecore Experience PlatformAI21/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform…
AplazadaMedia (4.3)0.20%—Brainstormforce SureformsAI20/9/202517/6/2026
The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPress is vulnerable to unauthorized creation of forms due to a missing capability check on the register_post_types() function in all versions up to, and including, 1.12.0. This makes it possible for…
AnalizadaMedia (6.9)0.37%—Liferay Digital Experience PlatformLiferay Portal19/9/202517/6/2026
The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and 7.3 service pack 3 through update 35 saves virtual products uploaded to Documents and Media with guest view permission, which allows remote…
AnalizadaMedia (5.1)0.18%—Liferay Digital Experience PlatformLiferay Portal19/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.7, 2023.Q3.1 through 2023.Q3.9, 7.4 GA through update 92, and older unsupported versions allows remote attackers…
AnalizadaMedia (6.9)0.28%—Liferay Digital Experience PlatformLiferay Portal19/9/202517/6/2026
Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.6, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions allows remote attackers to…