Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3246▲ 702 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.9%💥 ExploitPowerportal31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attackers to inject arbitrary web script or HTML via the (1) SUBJECT or (2) MESSAGE field.
ModificadaMedia (4.3)4.6%💥 ExploitCodeworx Technologies Dcp-portal31/12/200416/6/2026
CRLF injection vulnerability in calendar.php in DCP-Portal 5.3.2 and earlier allows remote attackers to conduct HTTP response splitting attacks to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the PHPSESSID parameter.
ModificadaMedia (4.3)5.3%💥 ExploitCodeworx Technologies Dcp-portal31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the year, (2) month, and (3) day parameters in calendar.php; (4) the cid and (5) url parameters in index.php; (6) the cid parameter in annoucement.php; (7) the cid…
ModificadaMedia (4.3)1.3%—Silent-storm Portal31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter.
ModificadaAlta (7.5)6.8%💥 ExploitSilent-storm PortalAI31/12/200416/6/2026
profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator.
ModificadaMedia (5)1.5%—Hitachi Cosminexus Portal FrameworkAI31/12/200416/6/2026
Unknown vulnerability in Hitachi Cosminexus Portal Framework 01-00, 01-01, 01-02, 02-01, 02-02, 02-03, and other versions allows remote attackers to obtain sensitive information in the <ut:cache> tag library.
ModificadaAlta (7.5)1.7%💥 ExploitMambo Portal31/12/200416/6/2026
SQL injection vulnerability in the ReMOSitory Server add-on module to Mambo Portal 4.5.1 (1.09) and earlier allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in the com_remository option.
ModificadaMedia (4.3)2.3%💥 Exploit2wire Homeportal31/12/200416/6/2026
Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error.
ModificadaAlta (7.5)3.1%💥 ExploitOcportal31/12/200416/6/2026
PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.
ModificadaMedia (5)59%💥 ExploitNortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+1523/12/200416/6/2026
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number…
ModificadaMedia (5)7.3%💥 ExploitAprox PHP PortalAI23/11/200416/6/2026
Vulnerabilidad de atravesamiento de directorios en index.php de Aprox PHP Portal permite a atacantes remotos la lectura de ficheros arbitrarios mediante su ruta completa en el parámetro show.
ModificadaMedia (6.8)2.1%💥 ExploitMaxwebportal23/11/200416/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en MaxWebPortal permite a atacantes remotos ejecutar script de su elección como otros usuarios mediante (1) el parámetro sub_name de dl_showall.asp, (2) el parámetro SentTo en Mensajes Personales, (3) el HTTP_REFERER de down.asp, o (4) en…
ModificadaAlta (7.5)1.3%—Maxwebportal23/11/200416/6/2026
Vulnerabilidad de inyección de SQL en MaxWebPortal permite a atacantes remotos inyectar código SQL arbitrario de su elección y obtener información sensible mediante el parámetro SendTo en Mensajes Personales.
ModificadaAlta (7.5)2.7%💥 ExploitCoolphp WEB Portal16/10/200416/6/2026
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files and execute local PHP scripts via a .. (dot dot) in the op parameter.
ModificadaMedia (4.3)1.3%—Coolphpweb Portal16/10/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.
ModificadaAlta (7.5)1.5%—CA Unicenter Management PortalAI21/9/200416/6/2026
The "Forgot your Password" link in Computer Associates (CA) Unicenter Management Portal 2.0 and 3.1 displays different error messages for users that exist and users that do not exist, which could allow remote attackers to guess valid usernames.
ModificadaMedia (5)34%—Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+1418/8/200416/6/2026
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by…
ModificadaMedia (5)1.5%—Powerportal6/8/200416/6/2026
PowerPortal 1.x allows remote attackers to gain sensitive information via invalid or missing parameters in HTTP requests to (1) resize.php or (2) modules.php, which reveals the path in an error message.
ModificadaMedia (5)7.3%💥 ExploitPowerportal6/8/200416/6/2026
Directory traversal vulnerability in modules.php in PowerPortal 1.x allows remote attackers to list arbitrary directories via a .. (dot dot) in the files parameter.
ModificadaMedia (6.8)2.0%—Powerportal6/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in modules.php in PowerPortal 1.x allows remote attackers to inject arbitrary script or HTML via the (1) id parameter to the (a) private_messages module; (2) search parameter to the (b) links and (c) content modules; and (3) files parameter to the gallery module.
ModificadaAlta (7.2)2.6%💥 ExploitOracle Application ServerOracle Application Server PortalOracle Database Server LiteOracle8i+130/7/200416/6/2026
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
ModificadaAlta (7.5)2.7%💥 ExploitJportal WEB Portal28/5/200416/6/2026
SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)2.1%💥 ExploitLiferay Enterprise Portal22/5/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote attackers to inject arbitrary web script or HTML, as demonstrated using the message subject.
ModificadaMedia (6.8)8.1%—Microsoft Sharepoint Portal Server4/5/200416/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Microsoft SharePoint Portal Server 2001 permite a atacantes remotos procesar contenido web elegido arbitrariamente y robar galletitas (cookies) mediante ciertos scripts de servidor.
ModificadaMedia (5)2.8%💥 ExploitIatek Portalapp4/1/200416/6/2026
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to gain access to sensitive information via a direct request to 8275.mdb.