Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

8646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.74%—Accela Automation Platform19/9/202517/6/2026
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, improper input validation allows for arbitrary file write and server-side request…
AnalizadaMedia (5.5)0.97%—Four-faith Water Conservancy Informatization19/9/202517/6/2026
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this vulnerability is an unknown functionality of the file /history/historyDownload.do;usrlogout.do. The manipulation of the argument fileName leads to path traversal. Remote exploitation of the attack…
AnalizadaMedia (5.5)0.97%—Four-faith Water Conservancy Informatization19/9/202530/9/2026
Una vulnerabilidad fue detectada en Four-Faith Water Conservancy Informatization Platform 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /history/historyDownload.do;otheruserLogin.do;getfile. La manipulación del argumento fileName resulta en salto de ruta. El ataque puede ser ejecutado…
AplazadaAlta (8.8)0.88%—Embed PDF FOR WpformsAI19/9/202517/6/2026
The Embed PDF for WPForms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_handler_download_pdf_media function in all versions up to, and including, 1.1.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload…
AplazadaMedia (4.7)0.23%—Pusula Communication Information Manageable Email Sending SystemAI19/9/202517/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client. This issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform18/9/202517/6/2026
A weakness has been identified in fuyang_lipengjun platform 1.0. Affected is the function BrandController of the file /brand/queryAll. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform18/9/202517/6/2026
A security flaw has been discovered in fuyang_lipengjun platform 1.0. This impacts the function AttributeController of the file /attribute/queryAll. Performing manipulation results in improper authorization. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform18/9/202517/6/2026
A vulnerability was identified in fuyang_lipengjun platform 1.0. This affects the function AttributeCategoryController of the file /attributecategory/queryAll. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.59%—Itsourcecode Student Information Management System18/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/class/index.php. This manipulation of the argument classId causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed…
AplazadaCrítica (9.8)0.36%—Esbi Information AND Telecommunication Industry AND Trade Limited Company Auto Service SoftwareAI18/9/202517/6/2026
CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection. This issue affects Auto Service Software: before v.2025.10.01.
AnalizadaCrítica (9.8)0.54%—Ninjaforms Ninja Forms18/9/202517/6/2026
The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog.
AnalizadaBaja (2.1)0.34%—Janobe Online Exam Form Submission18/9/202517/6/2026
A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/delete_user.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
AnalizadaBaja (2.1)0.34%—Janobe Online Exam Form Submission18/9/202517/6/2026
A flaw has been found in SourceCodester Online Exam Form Submission 1.0. Affected by this issue is some unknown functionality of the file /admin/update_s3.php. This manipulation of the argument credits causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AnalizadaBaja (2.1)0.34%—Janobe Online Exam Form Submission17/9/202525/9/2026
Se detectó una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /user/dashboard.php?page=update_profile. La manipulación del argumento 'phone' resulta en inyección SQL. El ataque puede ser lanzado remotamente. El exploit es…
AnalizadaBaja (2.1)0.34%—Facebook-julykringcadayona Student Information System17/9/202525/9/2026
Se ha encontrado una vulnerabilidad en itsourcecode Student Information System 1.0. El elemento afectado es una función desconocida del archivo /leveledit1.php. Dicha manipulación del argumento level_id conduce a inyección SQL. El ataque puede realizarse de forma remota. El exploit se ha divulgado al público y puede…
AnalizadaBaja (2.1)0.34%—Janobe Online Exam Form Submission17/9/202525/9/2026
Se encontró una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /admin/delete_s1.PHP. Realizar la manipulación del argumento ID resulta en inyección SQL. El ataque puede iniciarse remotamente. El exploit se ha hecho público…
AnalizadaMedia (5.5)0.42%—Janobe Online Exam Form Submission17/9/202525/9/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Afecta a una función desconocida del archivo /admin/index.php. Dicha manipulación del argumento email conduce a inyección SQL. Es posible lanzar el ataque de forma remota. El exploit ha sido divulgado al público y puede ser…
AnalizadaMedia (5.5)0.46%—Janobe Online Exam Form Submission17/9/202525/9/2026
Se ha encontrado una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Esto afecta a una función desconocida del archivo /register.PHP. Esta manipulación del argumento 'img' provoca una carga sin restricciones. Es posible iniciar el ataque de forma remota. El exploit ha sido publicado y puede ser…
AnalizadaMedia (5.5)0.55%—Janobe Online Exam Form Submission17/9/202525/9/2026
Se encontró una vulnerabilidad en SourceCodester Online Exam Form Submission 1.0. Esto afecta una parte desconocida del archivo /index.php. La manipulación del argumento usn resulta en inyección SQL. El ataque puede lanzarse remotamente. El exploit se ha hecho público y podría utilizarse.
AplazadaCrítica (9.8)0.35%—Yordam Informatics Yordam Library Automation SystemAI17/9/202517/6/2026
La vulnerabilidad de Neutralización Inadecuada de Elementos Especiales utilizados en un Comando SQL ('Inyección SQL') en el Sistema de Automatización de Biblioteca Yordam de Yordam Informatics permite la inyección SQL. Este problema afecta al Sistema de Automatización de Biblioteca Yordam: desde 21.5 y 21.6 antes de…
AplazadaMedia (4.7)0.24%—Zirve Information Technologies INC Zirve NovaAI17/9/202525/9/2026
Neutralización Inadecuada de la Entrada Durante la Generación de Páginas Web (XSS o 'cross-site scripting') vulnerabilidad en Zirve Information Technologies Inc. Zirve Nova permite cross-site scripting (XSS). Este problema afecta a Zirve Nova: desde 235 hasta 20250131.
AnalizadaMedia (5.1)0.23%—Liferay Digital Experience PlatformLiferay Portal16/9/202517/6/2026
Cross-site scripting (XSS) vulnerability in Search widget in Liferay Portal 7.4.3.93 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_search_web_portlet_SearchPortlet_userId parameter.
AnalizadaMedia (6.9)0.29%—Liferay Digital Experience PlatformLiferay Portal16/9/202517/6/2026
Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, and 7.3 GA through update 35 does not perform an authorization check when users attempt to view a display page template, which allows remote attackers to view display page templates via crafted…
AnalizadaMedia (6.9)0.40%—Liferay Digital Experience PlatformLiferay Portal16/9/202517/6/2026
Unchecked input for loop condition vulnerability in XML-RPC in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to perform a…
AplazadaAlta (8.6)0.33%—E1 InformaticsAI16/9/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in E1 Informatics Web Application allows SQL Injection. This issue affects Web Application: through 20250916. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE…