Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.33% | — | Xuxueli Xxl-jobAI | 21/9/2026 | 24/9/2026 | A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Aplazada | Baja (2) | 0.33% | — | Xuxueli Xxl-jobAI | 21/9/2026 | 21/9/2026 | A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Management Interface. The manipulation of the argument name/author leads to cross site… | |
| Aplazada | Baja (2.1) | 0.39% | — | Xuxueli Xxl-jobAI | 13/9/2026 | 15/9/2026 | A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection. Remote exploitation of the attack is possible. The exploit has been publicly… | |
| Aplazada | Baja (2.1) | 0.35% | — | Xuxueli Xxl-jobAI | 12/9/2026 | 14/9/2026 | A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The… | |
| Aplazada | Baja (2) | 0.33% | — | Xuxueli Xxl-jobAI | 12/9/2026 | 18/9/2026 | A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Media (6.5) | 0.40% | — | Xuxueli Xxl-jobAI | 31/7/2026 | 9/9/2026 | A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request. | |
| Aplazada | Alta (7.1) | 0.51% | — | Xuxueli Xxl-jobAI | 21/7/2026 | 23/7/2026 | XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can enumerate log records across all job… | |
| Aplazada | Crítica (9.1) | 0.22% | 💥 PoC | Xxl-job-adminAI | 15/7/2026 | 16/7/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping | |
| Aplazada | Baja (2.9) | 0.42% | — | Xuxueli Xxl-jobAI | 28/4/2026 | 24/7/2026 | A security vulnerability has been detected in Xuxueli xxl-job up to 3.3.2. The impacted element is an unknown function of the file xxl-job-admin/src/main/java/com/xxl/job/admin/scheduler/openapi/OpenApiController.java of the component OpenAPI Endpoint. Such manipulation of the argument default_token leads to use of… | |
| Aplazada | Baja (2.1) | 0.37% | — | Xuxueli Xxl-jobAI | 28/4/2026 | 24/7/2026 | A weakness has been identified in Xuxueli xxl-job up to 3.3.2. The affected element is the function triggerJob of the file xxl-job-admin/src/main/java/com/xxl/job/admin/service/impl/XxlJobServiceImpl.java of the component trigger Endpoint. This manipulation of the argument addressList causes server-side request… | |
| Aplazada | Baja (2.9) | 0.66% | — | Xuxueli Xxl-jobAI | 28/4/2026 | 24/7/2026 | A security flaw has been discovered in Xuxueli xxl-job up to 3.3.2. Impacted is the function logDetailCat of the file xxl-job-admin/src/main/java/com/xxl/job/admin/controller/biz/JobLogController.java of the component Execution Log Handler. The manipulation of the argument logId results in improper control of resource… | |
| Aplazada | Baja (2.1) | 0.38% | — | Xuxueli Xxl-jobAI | 8/3/2026 | 17/6/2026 | A vulnerability was detected in xuxueli xxl-job up to 3.3.2. This impacts an unknown function of the file source-code/src/main/java/com/xxl/job/admin/controller/JobInfoController.java. The manipulation results in server-side request forgery. It is possible to launch the attack remotely. The exploit is now public and… | |
| Analizada | Baja (2.1) | 0.35% | — | Xuxueli Xxl-job | 21/8/2025 | 17/6/2026 | A vulnerability was found in Xuxueli xxl-job up to 3.1.1. Affected by this issue is the function remove of the file /src/main/java/com/xxl/job/admin/controller/JobInfoController.java of the component Jobs Handler. Performing manipulation of the argument ID results in improper control of resource identifiers. Remote… | |
| Analizada | Baja (2.1) | 0.32% | — | Xuxueli Xxl-job | 20/8/2025 | 17/6/2026 | A vulnerability has been found in Xuxueli xxl-job up to 3.1.1. Affected by this vulnerability is the function getJobsByGroup of the file /src/main/java/com/xxl/job/admin/controller/JobLogController.java. Such manipulation of the argument jobGroup leads to improper control of resource identifiers. The attack may be… | |
| Analizada | Baja (2.9) | 0.29% | — | Xuxueli Xxl-job | 18/7/2025 | 17/6/2026 | A vulnerability was found in Xuxueli xxl-job up to 3.1.1 and classified as problematic. Affected by this issue is the function makeToken of the file src/main/java/com/xxl/job/admin/controller/IndexController.java of the component Token Generation. The manipulation leads to password hash with insufficient computational… | |
| Analizada | Baja (2.1) | 4.9% | — | Xuxueli Xxl-job | 18/7/2025 | 17/6/2026 | A vulnerability has been found in Xuxueli xxl-job up to 3.1.1 and classified as critical. Affected by this vulnerability is the function commandJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to os command injection. The attack can be launched… | |
| Analizada | Baja (2.1) | 0.44% | — | Xuxueli Xxl-job | 18/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Xuxueli xxl-job up to 3.1.1. Affected is the function httpJobHandler of the file src\main\java\com\xxl\job\executor\service\jobhandler\SampleXxlJob.java. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely.… | |
| Modificada | Alta (8.8) | 0.89% | — | Xuxueli Xxl-job | 15/8/2024 | 17/6/2026 | Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component. | |
| Analizada | Crítica (9.8) | 0.95% | — | Xuxueli Xxl-job | 6/4/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Xuxueli xxl-job up to 2.4.1. This vulnerability affects the function deserialize of the file com/xxl/job/core/util/JdkSerializeTool.java of the component Template Handler. The manipulation leads to injection. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 0.56% | — | Xuxueli Xxl-job | 8/2/2024 | 17/6/2026 | xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE. | |
| Modificada | Alta (8.8) | 1.3% | — | Xuxueli Xxl-job | 15/11/2023 | 17/6/2026 | xxl-job-admin 2.4.0 is vulnerable to Remote Code Execution (RCE) via /xxl-job-admin/jobcode/save. | |
| Modificada | Media (5.4) | 0.40% | — | Xuxueli Xxl-job | 15/11/2023 | 17/6/2026 | xxl-job-admin 2.4.0 is vulnerable to Cross Site Scripting (XSS) via /xxl-job-admin/joblog/logDetailPage. | |
| Modificada | Media (5.4) | 0.36% | — | Xuxueli Xxl-job | 15/11/2023 | 17/6/2026 | xxl-job-admin 2.4.0 is vulnerable to Insecure Permissions via /xxl-job-admin/joblog/clearLog and /xxl-job-admin/joblog/logDetailCat. | |
| Modificada | Alta (8.8) | 0.50% | — | Xuxueli Xxl-job | 11/8/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in xxl-job-admin/user/add in xuxueli xxl-job version 2.2.0, allows remote attackers to execute arbitrary code and esclate privileges via crafted .html file. | |
| Modificada | Alta (8.8) | 0.95% | — | Xuxueli Xxl-job | 26/5/2023 | 9/7/2026 | A lateral privilege escalation vulnerability in XXL-Job v2.4.1 allows users to execute arbitrary commands on another user's account via a crafted POST request to the component /jobinfo/. |