Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3077▲ 492 respecto a la semana anterior
Críticas / altas1455▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

8646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.22%💥 PoCUbit Information Technologies StoysAI16/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ubit Information Technologies STOYS allows Cross-Site Scripting (XSS). This issue affects STOYS: from 2 before 20250916.
AplazadaBaja (2.3)0.33%—Form TO DatabaseAI16/9/202517/6/2026
The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: before 2.2.5, from 3.0.0 before 3.2.2, from 4.0.0 before 4.2.3, from 5.0.0 before 5.0.2.
AnalizadaMedia (4.8)0.27%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in a custom object’s /o/c/<object-name> API endpoint in Liferay Portal 7.4.3.51 through 7.4.3.109, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 update 51 through update 92, and 7.3 update 33 through update 35. allows remote attackers to inject arbitrary web script or…
AnalizadaMedia (5.3)0.25%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
In Liferay Portal 7.1.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions, the default membership type of a newly created site is “Open” which allows any registered users to become a member of the site. A remote…
AnalizadaMedia (6.9)0.26%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35, and older unsupported versions does not limit access to APIs before a user has changed their initial password, which allows remote users…
AnalizadaBaja (2.1)0.18%—Liferay Digital Experience Platform15/9/202517/6/2026
Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TOTP) to be used multiple times during the validity period, which allows attackers with access to a user’s TOTP to authenticate as the user.
AnalizadaMedia (4.8)0.23%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Cross-site scripting (XSS) vulnerability in Objects in Liferay Portal 7.4.3.20 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4 and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into an object with a rich text type field.
AnalizadaMedia (4.8)0.22%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.3.0 through 7.4.3.111, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 36 allow remote attackers to inject arbitrary web script or HTML via a crafted payload injected into a "Rich Text"…
AnalizadaBaja (2.3)0.32%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions does not properly obtain the remote address of the live site from the database which,…
AplazadaAlta (8.5)0.20%—Digilent WaveformsAI15/9/202517/6/2026
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent WaveForms 3.24.3 and prior versions.
AnalizadaMedia (6.9)0.40%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions may incorrectly identify the subdomain of a domain name and create a supercookie, which allows remote…
AplazadaAlta (7.3)0.14%—Piriform CcleanerAI15/9/202517/6/2026
Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows allows a local user to gain SYSTEM privileges via exploiting insecure file delete operations. Reported in CCleaner v. 6.33.11465. This issue affects CCleaner: before < 6.36.11508.
AnalizadaMedia (4.6)0.23%—Liferay Digital Experience PlatformLiferay Portal15/9/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote authenticated attackers with the instance…
AnalizadaMedia (5.5)0.43%—Itsourcecode Baptism Information Management System14/9/202517/6/2026
A vulnerability was found in itsourcecode Baptism Information Management System 1.0. This impacts an unknown function of the file /rptbaptismal.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.41%—Itsourcecode Baptism Information Management System14/9/202530/9/2026
Se determinó una vulnerabilidad en itsourcecode Baptism Information Management System 1.0. Afectada es una función desconocida del archivo /listbaptism.PHP. Esta manipulación del argumento bapt_id causa inyección SQL. Es posible iniciar el ataque remotamente. El exploit ha sido divulgado públicamente y puede ser…
AnalizadaMedia (5.3)0.38%—Huggingface Transformers14/9/202530/9/2026
Se descubrió una vulnerabilidad de denegación de servicio por expresión regular (ReDoS) en la biblioteca Hugging Face Transformers, específicamente dentro del método 'normalize_numbers()' de la clase 'EnglishNormalizer'. Esta vulnerabilidad afecta a las versiones hasta la 4.52.4 y está corregida en la versión 4.53.0.…
AnalizadaBaja (2.3)0.12%—IBM Qradar Security Information AND Event Manager14/9/202517/6/2026
IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configuration files due to improper permission assignment.
AnalizadaAlta (7.1)0.38%—Liferay Digital Experience PlatformLiferay Portal12/9/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.101, and Liferay DXP 2023.Q3.0 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA though update 35 does not limit the number of objects returned from a GraphQL queries, which allows remote attackers to perform denial-of-service (DoS) attacks on the application by executing…
AnalizadaMedia (5.1)0.24%—Liferay Digital Experience PlatformLiferay Portal12/9/202517/6/2026
Open redirect vulnerability in the System Settings in Liferay Portal 7.1.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4 , 7.4 GA through update 92, 7.3 GA through update 35, and older unsupported versions allows remote attackers to redirect users to arbitrary external URLs via the…
AnalizadaMedia (5.1)0.22%—Liferay Digital Experience PlatformLiferay Portal12/9/202517/6/2026
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q3.0, 2025.Q2.0 through 2025.Q2.12, 2025.Q1.0 through 2025.Q1.17, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote…
AnalizadaAlta (7.5)0.53%—Huggingface Transformers12/9/202517/6/2026
A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language_code()` method. This vulnerability is present in version 4.52.4 and has been fixed in version 4.53.0. The issue arises from inefficient…
AnalizadaMedia (5.8)0.20%—Iambriansreed Contact Form 7 Recaptcha12/9/202530/9/2026
El plugin de WordPress Contact Form 7 reCAPTCHA hasta la versión 1.2.0 no escapa el parámetro $_SERVER['REQUEST_URI'] antes de devolverlo en un atributo, lo que podría conducir a cross-site scripting reflejado en navegadores web antiguos.
AnalizadaBaja (1)0.22%—Liferay Digital Experience PlatformLiferay Portal12/9/202517/6/2026
JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSGi are registered and invoked directly as classes which allows Service Access Policies get executed.
AnalizadaMedia (5.3)0.27%—Liferay Digital Experience PlatformLiferay Portal12/9/202517/6/2026
The organization selector in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q1.1 through 2024.Q1.12 and 7.4 update 81 through update 85 does not check user permission, which allows remote authenticated users to obtain a list of all organizations.
AnalizadaAlta (7.4)0.34%—Liferay Digital Experience PlatformLiferay Portal11/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.6, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows remote authenticated users to from one virtual instance to access, create, edit, relate data/object…