Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.24% | — | Intrexx | 2/5/2025 | 17/6/2026 | In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaScript code in HTML, aka XSS. | |
| Aplazada | Media (6.1) | 0.23% | — | Intrexx Portal ServerAI | 19/3/2025 | 17/6/2026 | Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts. | |
| Aplazada | Media (6.5) | 0.34% | — | Intrexx Portal ServerAI | 19/3/2025 | 17/6/2026 | A vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular permissions under certain conditions to see potentially sensitive data from a different user context. | |
| Aplazada | Media (5.4) | 0.22% | — | Intrexx Portal ServerAI | 16/12/2024 | 17/6/2026 | Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet. | |
| Modificada | Media (6.1) | 0.83% | — | Unitedplanet Intrexx | 14/10/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter. | |
| Modificada | Crítica (9.8) | 4.0% | — | Unitedplanet Intrexx | 31/1/2020 | 17/6/2026 | Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unknown vectors. | |
| Modificada | Media (4.3) | 1.9% | — | Unitedplanet Intrexx | 19/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter. |