Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
–

8647 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—Course Finder Course Booking PlatformAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Course Finder | andré martin - it solutions & research UG Course Booking Platform course-booking-platform allows Stored XSS.This issue affects Course Booking Platform: from n/a through <= 1.0.0.
AplazadaMedia (6.5)0.21%—Givecloud Donation Forms WPAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in givecloud Donation Forms WP by Givecloud donation-forms-by-givecloud allows Stored XSS.This issue affects Donation Forms WP by Givecloud: from n/a through <= 1.0.9.
AplazadaMedia (5.9)0.22%—Habibur Rahman Comment Form WPAI5/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Comment Form WP – Customize Default Comment Form comment-form-wp allows Stored XSS.This issue affects Comment Form WP – Customize Default Comment Form: from n/a through <= 2.0.1.
AnalizadaBaja (2.1)0.36%—Fuyang Lipengjun Platform4/9/202517/6/2026
A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the file /ad/queryAll. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
AplazadaAlta (7.1)0.52%—Liferay DXPAILiferay Kaleo Forms AdminAILiferay PortalAI4/9/202517/6/2026
Kaleo Forms Admin in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.4 GA, 7.3 GA through update 27, and older unsupported versions does not restrict the saving of request parameters in the portlet session, which allows remote attackers to consume system memory leading to denial-of-service (DoS) conditions via…
AnalizadaCrítica (9)53%⚠ Explotación activa💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This issue affects Experience Manager (XM): through 9.0; Experience Platform (XP): through 9.0.
AnalizadaMedia (6.7)0.14%—IBM Transformation Advisor3/9/202517/6/2026
IBM Transformation Advisor 2.0.1 through 4.3.1 incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Transformation Advisor Operator Catalog image.
AnalizadaAlta (7.5)6.5%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP).This issue affects Sitecore Experience Manager (XM): from 9.2 through 10.4; Experience Platform (XP): from 9.2 through 10.4.
AnalizadaCrítica (9.8)20%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cache Poisoning.This issue affects Sitecore Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform…
AnalizadaAlta (8.8)1.6%💥 PoCSitecore Experience CommerceSitecore Experience ManagerSitecore Experience PlatformSitecore Managed Cloud3/9/202517/6/2026
Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Remote Code Execution (RCE).This issue affects Experience Manager (XM): from 9.0 through 9.3, from 10.0 through 10.4; Experience Platform (XP): from 9.0 through 9.3, from 10.0 through 10.4.
AplazadaMedia (5.4)0.22%—Contact Form BY Mega FormsAI3/9/202530/9/2026
Vulnerabilidad de autorización faltante en Ali Khallad Contact Form By Mega Forms permite la explotación de niveles de seguridad de control de acceso configurados incorrectamente. Este problema afecta a Contact Form By Mega Forms: desde n/a hasta 1.6.1.
AplazadaMedia (6.5)0.21%—PDF FOR WpformsAI3/9/202530/9/2026
Vulnerabilidad de Neutralización Incorrecta de la Entrada durante la Generación de Páginas Web ('cross-site scripting') en add-ons.org PDF for WPForms permite XSS almacenado. Este problema afecta a PDF for WPForms: desde n/a hasta la 6.2.1.
AnalizadaAlta (8.8)8.6%—Openagentplatform Dive3/9/202517/6/2026
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code Execution vulnerability triggered through a custom url value, `transport` in the JSON object. An attacker can exploit the vulnerability in the…
AplazadaMedia (6.5)0.58%—Fluentforms Fluent FormsAI3/9/202517/6/2026
The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to PHP Object Injection in versions 5.1.16 to 6.1.1 via deserialization of untrusted input in the parseUserProperties function. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A security flaw has been discovered in itsourcecode Student Information Management System 1.0. The affected element is an unknown function of the file /admin/modules/course/index.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has…
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
AnalizadaMedia (5.5)0.42%—Itsourcecode Student Information Management System2/9/202517/6/2026
A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. This manipulation of the argument studentId causes sql injection. The attack may be initiated remotely. The exploit has been publicly…
ModificadaAlta (7.5)2.3%💥 PoCRedhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+42/9/20256/10/2026
Se encontró una vulnerabilidad en Undertow donde solicitudes de cliente malformadas pueden desencadenar restablecimientos de flujo del lado del servidor sin activar contadores de abuso. Este problema, conocido como el ataque “MadeYouReset”, permite a clientes maliciosos inducir una carga de trabajo excesiva del…
AnalizadaAlta (7.5)0.42%—Liferay Digital Experience PlatformLiferay Portal1/9/202517/6/2026
In Liferay Portal 7.4.3.27 through 7.4.3.42, and Liferay DXP 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 update 27 through update 42 (Liferay PaaS, and Liferay Self-Hosted), the Objects module does not restrict the use of Groovy scripts in Object actions for Admin…
AnalizadaMedia (5.5)0.41%—Facebook-julykringcadayona Student Information System30/8/202517/6/2026
A security vulnerability has been detected in itsourcecode Student Information System 1.0. This affects an unknown function of the file /course_edit1.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
AnalizadaMedia (4.6)0.29%—Liferay Digital Experience PlatformLiferay Portal29/8/202517/6/2026
Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.18 and 7.4 GA through update 92 has a security vulnerability that allowing for improper access through the…
AplazadaMedia (6.5)0.30%—Iats Online FormsAI29/8/202517/6/2026
The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all versions up to, and including, 1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
AnalizadaBaja (2.1)0.40%—Itsourcecode Student Information Management System29/8/202517/6/2026
A vulnerability was found in code-projects Student Information Management System 1.0. The impacted element is an unknown function of the file /login.php. The manipulation of the argument uname results in cross site scripting. The attack may be performed from a remote location. The exploit has been made public and…
AplazadaBaja (2)0.26%—Weaver E-mobile Mobile Management PlatformAI28/8/202525/9/2026
Se identificó una vulnerabilidad en la Plataforma de Gestión Móvil Weaver E-Mobile hasta el 20250813. Una funcionalidad desconocida se ve afectada por esta vulnerabilidad. La manipulación del argumento gohome conduce a Cross-Site Scripting. El ataque puede iniciarse de forma remota. El exploit está disponible…
AnalizadaMedia (6.1)0.21%—Formcms28/8/202525/9/2026
FormCms v0.5.5 contiene una vulnerabilidad de cross-site scripting (XSS) almacenada en la función de subida de avatares. Usuarios autenticados pueden subir archivos .html que contienen JavaScript malicioso, los cuales son accesibles a través de una URL pública. Cuando un usuario privilegiado accede al archivo, el…