Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

8646 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.33%—Liferay Digital Experience PlatformLiferay Portal11/9/202517/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in Liferay Portal 7.4.0 through 7.4.3.124, and Liferay DXP 2024.Q2.0 through 2024.Q2.7, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote authenticated users to access a workflow definition by name via the API
AplazadaAlta (7.1)0.34%—Angular Platform ServerAIAngular SSRAI10/9/202517/6/2026
Angular es una plataforma de desarrollo para construir aplicaciones web móviles y de escritorio usando TypeScript/JavaScript y otros lenguajes. Angular usa un contenedor DI (el 'inyector de plataforma') para mantener el estado específico de la solicitud durante la renderización del lado del servidor. Por razones…
AnalizadaMedia (6.8)0.21%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a privileged user to escalate their privileges and attack surface on the host due to the containers running with unnecessary privileges.
AnalizadaAlta (7.5)0.19%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
AnalizadaMedia (6.5)0.37%—IBM Security Verify Information Queue10/9/202517/6/2026
IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 could allow a remote user to cause a denial of service due to improper handling of special characters that could lead to uncontrolled resource consumption.
AnalizadaMedia (5.1)0.24%—Liferay Digital Experience PlatformLiferay Portal10/9/202525/9/2026
Vulnerabilidad de cross-site scripting (XSS) reflejada en Liferay Portal 7.4.3.73 hasta 7.4.3.128, y Liferay DXP 2024.Q3.0 hasta 2024.Q3.1, 2024.Q2.0 hasta 2024.Q2.13, 2024.Q1.1 hasta 2024.Q1.12, 7.4 actualización 73 hasta actualización 92 permite a atacantes remotos inyectar script web o HTML arbitrario a través de…
AnalizadaMedia (6.2)0.26%—Liferay Digital Experience PlatformLiferay Portal10/9/202525/9/2026
Vulnerabilidad de control de acceso inadecuado en Liferay Portal 7.4.0 hasta 7.4.3.124, y Liferay DXP 2024.Q2.0 hasta 2024.Q2.8, 2024.Q1.1 hasta 2024.Q1.12 y 7.4 GA hasta la actualización 92 permite a los usuarios invitados obtener información de entradas de objetos a través del API Builder.
AnalizadaMedia (4.6)0.22%—Liferay Digital Experience PlatformLiferay Portal10/9/202525/9/2026
Vulnerabilidad de cross-site scripting (XSS) almacenado en Liferay Portal 7.4.3.45 hasta 7.4.3.128, y Liferay DXP 2024 Q2.0 hasta 2024.Q2.9, 2024.Q1.1 hasta 2024.Q1.12, y 7.4 actualización 45 hasta actualización 92 permite a atacantes remotos ejecutar un script web o HTML arbitrario en la página My Workflow Tasks.
AnalizadaMedia (5.4)0.19%—Pega Platform10/9/202525/9/2026
Las versiones de Pega Platform 7.1.0 hasta Infinity 24.2.2 están afectadas por un problema de XSS Almacenado en un componente de la interfaz de usuario. Requiere un usuario con altos privilegios y rol de desarrollador.
AnalizadaMedia (6.9)0.31%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
Enumeration of ERC from object entry in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 allow attackers to determine existent ERC in the application by exploit the time response.
AnalizadaMedia (5.3)0.23%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.110 through 7.4.3.128, and Liferay DXP 2024.Q3.1 through 2024.Q3.8, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.12 allows remote attackers to inject arbitrary web script or HTML via the URL in search bar portlet
AnalizadaMedia (4.6)0.22%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.128, and Liferay DXP 2024.Q3.0 through 2024.Q3.5, 2024.Q2.0 through 2024.Q2.12, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 allows remote attackers to inject arbitrary web script or HTML via remote app title field.
AplazadaMedia (6.5)0.17%—Silverplugins217 Dynamic Text Field FOR Contact Form 7AI9/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in silverplugins217 Dynamic Text Field For Contact Form 7 dynamic-text-field-for-contact-form-7 allows Stored XSS.This issue affects Dynamic Text Field For Contact Form 7: from n/a through <= 1.0.
AnalizadaMedia (4.6)0.21%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.19 and 7.4 GA through update 92 allows…
AnalizadaMedia (5.1)0.24%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.19 exposes "Internal Server Error" in the response body when a login attempt is made…
AnalizadaMedia (4.8)0.23%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.11, 2025.Q1.0 through 2025.Q1.16, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 allows an remote authenticated…
AplazadaMedia (6.1)0.22%—SAP Netweaver Abap PlatformAI9/9/202517/6/2026
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP NetWeaver ABAP Platform, an unauthenticated attacker could generate a malicious link and make it publicly accessible. If an authenticated user clicks on this link, the injected input is processed during the website�s page generation, resulting in the…
AnalizadaMedia (4.8)0.20%—Liferay Digital Experience PlatformLiferay Portal9/9/202517/6/2026
A server-side request forgery (SSRF) vulnerability exist in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.20 that affects custom object attachment fields. This flaw allows an attacker to…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information Management System 1.0. This affects an unknown function of the file /admin/modules/room/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System9/9/202517/6/2026
A weakness has been identified in itsourcecode Student Information Management System 1.0. The impacted element is an unknown function of the file /admin/modules/department/index.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System8/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/instructor/index.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to…
AnalizadaBaja (2.1)0.33%—Fuyang Lipengjun Platform8/9/202517/6/2026
A weakness has been identified in fuyang_lipengjun platform 1.0.0. This issue affects the function queryAll of the file /adposition/queryAll of the component AdPositionController. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit has been made available to the public…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System6/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part of the file /admin/login.php. Executing manipulation of the argument uname can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaAlta (7.2)0.66%—Mondula Multi Step FormAI6/9/202517/6/2026
The Multi Step Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the import functionality in all versions up to, and including, 1.7.25. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the…
AplazadaMedia (6.5)0.17%—Course Finder Course Booking PlatformAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0.