Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
8647 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Course Finder Course Booking PlatformAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Givecloud Donation Forms WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in givecloud Donation Forms WP by Givecloud donation-forms-by-givecloud allows Stored XSS.This issue affects Donation Forms WP by Givecloud: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.9) | 0.22% | — | Habibur Rahman Comment Form WPAI | 5/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Comment Form WP – Customize Default Comment Form comment-form-wp allows Stored XSS.This issue affects Comment Form WP – Customize Default Comment Form: from n/a through <= 2.0.1. | |
| Analizada | Baja (2.1) | 0.36% | — | Fuyang Lipengjun Platform | 4/9/2025 | 17/6/2026 | A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |
| Aplazada | Alta (7.1) | 0.52% | — | Liferay DXPAILiferay Kaleo Forms AdminAILiferay PortalAI | 4/9/2025 | 17/6/2026 | Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via… | |
| Analizada | Crítica (9) | 53% | ⚠ Explotación activa💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0. | |
| Analizada | Media (6.7) | 0.14% | — | IBM Transformation Advisor | 3/9/2025 | 17/6/2026 | IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image. | |
| Analizada | Alta (7.5) | 6.5% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4. | |
| Analizada | Crítica (9.8) | 20% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform… | |
| Analizada | Alta (8.8) | 1.6% | 💥 PoC | Sitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud | 3/9/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4. | |
| Aplazada | Media (5.4) | 0.22% | — | Contact Form BY Mega FormsAI | 3/9/2025 | 30/9/2026 | Vulnerabilidad de autorización faltante en Ali Khallad Contact Form By Mega Forms permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Contact Form By Mega Forms: desde n/a hasta 1.6.1. | |
| Aplazada | Media (6.5) | 0.21% | — | PDF FOR WpformsAI | 3/9/2025 | 30/9/2026 | Vulnerabilidad de Neutralización Incorrecta de la Entrada durante la Generación de Páginas Web ('cross-site scripting') en add-ons.org PDF for WPForms permite XSS almacenado. Este problema afecta a PDF for WPForms: desde n/a hasta la 6.2.1. | |
| Analizada | Alta (8.8) | 8.6% | — | Openagentplatform Dive | 3/9/2025 | 17/6/2026 | Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code Execution vulnerability triggered through a custom url value, `transport` in the JSON object. An attacker can exploit the vulnerability in the… | |
| Aplazada | Media (6.5) | 0.58% | — | Fluentforms Fluent FormsAI | 3/9/2025 | 17/6/2026 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.42% | — | Itsourcecode Student Information Management System | 2/9/2025 | 17/6/2026 | A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly… | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 6/10/2026 | Se encontró una vulnerabilidad en Undertow donde solicitudes de cliente malformadas pueden desencadenar restablecimientos de flujo del lado del servidor sin activar contadores de abuso. Este problema, conocido como el ataque “MadeYouReset”, permite a clientes maliciosos inducir una carga de trabajo excesiva del… | |
| Analizada | Alta (7.5) | 0.42% | — | Liferay Digital Experience PlatformLiferay Portal | 1/9/2025 | 17/6/2026 | In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin… | |
| Analizada | Media (5.5) | 0.41% | — | Facebook-julykringcadayona Student Information System | 30/8/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (4.6) | 0.29% | — | Liferay Digital Experience PlatformLiferay Portal | 29/8/2025 | 17/6/2026 | Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the… | |
| Aplazada | Media (6.5) | 0.30% | — | Iats Online FormsAI | 29/8/2025 | 17/6/2026 | The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated… | |
| Analizada | Baja (2.1) | 0.40% | — | Itsourcecode Student Information Management System | 29/8/2025 | 17/6/2026 | A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and… | |
| Aplazada | Baja (2) | 0.26% | — | Weaver E-mobile Mobile Management PlatformAI | 28/8/2025 | 25/9/2026 | Se identificó una vulnerabilidad en la Plataforma de Gestión Móvil Weaver E-Mobile hasta el 20250813. Una funcionalidad desconocida se ve afectada por esta vulnerabilidad. La manipulación del argumento gohome conduce a Cross-Site Scripting. El ataque puede iniciarse de forma remota. El exploit está disponible… | |
| Analizada | Media (6.1) | 0.21% | — | Formcms | 28/8/2025 | 25/9/2026 | FormCms v0.5.5 contiene una vulnerabilidad de cross-site scripting (XSS) almacenada en la función de subida de avatares. Usuarios autenticados pueden subir archivos .html que contienen JavaScript malicioso, los cuales son accesibles a través de una URL pública. Cuando un usuario privilegiado accede al archivo, el… |