Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2881▼ 123 respecto a la semana anterior
Críticas / altas1393▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.35% | — | IshankportfolioAI | 11/8/2026 | 9/9/2026 | ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials or permissive database rules may allow… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 12/8/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.34% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpzoom PortfolioAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Portfolio wpzoom-portfolio allows Reflected XSS.This issue affects WPZOOM Portfolio: from n/a through <= 1.4.29. | |
| Analizada | Alta (8.8) | 0.43% | — | Myportfolio | 19/6/2026 | 19/8/2026 | Joomla Component Myportfolio 3.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the pid parameter. Attackers can send GET requests to index.php with malicious pid values in the task=project&view=grid endpoint to extract… | |
| Analizada | Alta (8.8) | 0.49% | — | Extro Responsive Portfolio | 19/6/2026 | 19/8/2026 | Joomla! Component RPC Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_pofos&view=pofo&id=[SQL] to extract… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Project Portfolio Analysis | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Project Portfolio Analysis | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Project Portfolio Analysis | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Aplazada | Alta (7.1) | 0.93% | — | Wpzoom PortfolioAI | 10/6/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio allows Reflected XSS. This issue affects WPZOOM Portfolio: from n/a through 1.4.21. | |
| Aplazada | Alta (7.1) | 0.28% | — | Joomla Responsive PortfolioAI | 25/5/2026 | 24/7/2026 | Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract… | |
| Aplazada | Media (5.1) | 0.19% | — | Filterable Portfolio GalleryAI | 10/5/2026 | 25/7/2026 | Filterable Portfolio Gallery 1.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript by entering payloads in the title field. Attackers can store JavaScript code like image tags with onerror handlers that execute when the gallery is previewed,… | |
| Aplazada | Baja (2.1) | 0.37% | — | 1000projects Portfolio Management System MCAAI | 27/4/2026 | 17/6/2026 | A security flaw has been discovered in 1000 Projects Portfolio Management System MCA 1.0. This impacts an unknown function of the file update_passwd_process.php. The manipulation of the argument temp_user results in authorization bypass. The attack can be launched remotely. The exploit has been released to the public… | |
| Aplazada | Baja (2.1) | 0.32% | — | 1000projects Portfolio Management System MCAAI | 27/4/2026 | 17/6/2026 | A vulnerability was identified in 1000 Projects Portfolio Management System MCA up to 1.0. This affects an unknown function of the file /admin/block_status.php. The manipulation of the argument q leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.4) | 0.14% | — | Themegoods Grand PortfolioAI | 8/4/2026 | 24/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ThemeGoods Grand Portfolio grandportfolio allows Cross Site Request Forgery.This issue affects Grand Portfolio: from n/a through <= 3.3. | |
| Aplazada | Alta (7.5) | 0.51% | — | NK Visual PortfolioAI | 25/3/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Visual Portfolio, Photo Gallery & Post Grid visual-portfolio allows PHP Local File Inclusion.This issue affects Visual Portfolio, Photo Gallery & Post Grid: from n/a through <= 3.5.1. | |
| Aplazada | Media (5.3) | 0.32% | — | Vowelweb VW PortfolioAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in vowelweb VW Portfolio vw-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Portfolio: from n/a through <= 1.3.3. | |
| Aplazada | Media (5.3) | 0.29% | — | Raratheme Perfect-portfolioAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in raratheme Perfect Portfolio perfect-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Perfect Portfolio: from n/a through <= 1.2.4. | |
| Aplazada | Alta (7.1) | 0.26% | — | Designthemes PortfolioAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio designthemes-portfolio allows Reflected XSS.This issue affects DesignThemes Portfolio: from n/a through <= 1.3. | |
| Aplazada | Alta (8.1) | 0.57% | — | Solverwp Portfolio BuilderAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SolverWp Portfolio Builder swp-portfolio allows PHP Local File Inclusion.This issue affects Portfolio Builder: from n/a through <= 1.2.5. | |
| Aplazada | Alta (8.5) | 0.29% | — | Themepassion Ultra PortfolioAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themepassion Ultra Portfolio ultra-portfolio allows Blind SQL Injection.This issue affects Ultra Portfolio: from n/a through <= 6.7. | |
| Aplazada | Media (5.9) | 0.17% | — | Eleopard Behance Portfolio ManagerAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eleopard Behance Portfolio Manager portfolio-manager-powered-by-behance allows Stored XSS.This issue affects Behance Portfolio Manager: from n/a through <= 1.7.5. |