Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.32% | — | Wellchoose Organization Portal System | 11/3/2026 | 17/6/2026 | IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Analizada | Media (5.1) | 0.33% | — | Wellchoose Organization Portal System | 11/3/2026 | 17/6/2026 | IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website. | |
| Analizada | Crítica (9.1) | 0.47% | — | Telekom Account Management Portal | 10/3/2026 | 17/6/2026 | Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-24, fixed 2025-11-03. | |
| Analizada | Crítica (9.4) | 0.40% | — | Telekom Account Management Portal | 10/3/2026 | 17/6/2026 | Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Account Management Portal, versions before 2025-10-27, fixed 2025-10-31. | |
| Pendiente de análisis | Crítica (9.1) | 0.64% | — | SAP Netweaver Enterprise PortalAI | 10/3/2026 | 17/6/2026 | SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system. | |
| Analizada | Alta (7.5) | 0.43% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Alta (8.8) | 0.16% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Modificada | Alta (7.5) | 0.35% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Media (6.1) | 0.24% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Media (5.4) | 0.24% | — | Sunbirded-portal | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. | |
| Analizada | Baja (2.1) | 0.49% | — | Carmelo Student WEB Portal | 8/3/2026 | 17/6/2026 | A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.61% | — | Carmelo Student WEB Portal | 8/3/2026 | 17/6/2026 | A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Alta (8.4) | 0.37% | — | Wikitide Tsportal | 6/3/2026 | 17/6/2026 | TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigations, appeals, and transparency work. Prior to version 30, conversion of empty strings to null allows disguising DPA reports as genuine self-deletion reports. This issue has been patched in version 30. | |
| Aplazada | Media (5.3) | 0.22% | — | Precurio Intranet PortalAI | 6/3/2026 | 17/6/2026 | Precurio Intranet Portal 2.0 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create administrative user accounts by submitting crafted POST requests. Attackers can forge requests to the /public/admin/user/submitnew endpoint with user creation parameters to add new admin… | |
| Analizada | Media (6.1) | 0.27% | — | Plone Isurlinportal | 5/3/2026 | 17/6/2026 | Products.isurlinportal is a replacement for isURLInPortal method in Plone. Prior to versions 2.1.0, 3.1.0, and 4.0.0, a url /login?came_from=////evil.example may redirect to an external website after login. This issue has been patched in versions 2.1.0, 3.1.0, and 4.0.0. | |
| Analizada | Alta (8.8) | 0.55% | — | Wgportal Wireguard Portal | 26/2/2026 | 17/6/2026 | WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2.1.3, any authenticated non-admin user can become a full administrator by sending a single PUT request to their own user profile endpoint with `"IsAdmin": true` in the JSON body. After logging out and… | |
| Analizada | Media (5.5) | 0.61% | — | Clive 21 News Portal Project | 25/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.59% | — | Clive 21 News Portal Project | 25/2/2026 | 17/6/2026 | A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.59% | — | Clive 21 News Portal Project | 25/2/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. The attack may be performed from remote. The exploit has been released to the… | |
| Modificada | Media (6.1) | 0.39% | — | Kashipara Society Management System Portal | 23/2/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers to inject and store arbitrary JavaScript code that is executed in users' browsers. This vulnerability can be exploited via the name parameter in a POST HTTP request,… | |
| Analizada | Baja (2.7) | 0.17% | — | Zscaler Internet Access Admin Portal | 23/2/2026 | 17/6/2026 | Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions. | |
| Analizada | Baja (2.7) | 0.20% | — | Zscaler Internet Access Admin Portal | 23/2/2026 | 17/6/2026 | Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios. | |
| Aplazada | Alta (8.8) | 0.36% | — | Microasp Portal Plus CMSAI | 22/2/2026 | 17/6/2026 | microASP Portal+ CMS contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the explode_tree parameter. Attackers can send crafted requests to pagina.phtml with SQL injection payloads using extractvalue and concat functions to… | |
| Analizada | Media (5.1) | 0.29% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user profile update workflow (user_settings.php submitting to admin/update_user.php). Authenticated users can store malicious HTML/JavaScript in fields such as Firstname, lastname, email, and image_url, which are later rendered… | |
| Analizada | Media (5.1) | 0.32% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user registration workflow (index.php submitting to admin/user_action.php). User-supplied fields such as Firstname, lastname, and email are stored in the backend database without adequate output encoding and are later rendered… |