Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.42% | — | Yzcheng90 X-springbootAI | 26/6/2025 | 17/6/2026 | A vulnerability was found in yzcheng90 X-SpringBoot up to 5.0 and classified as critical. Affected by this issue is the function uploadApk of the file /sys/oss/upload/apk of the component APK File Handler. The manipulation of the argument File leads to path traversal. The attack may be launched remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.41% | — | Java-aodeng Hope-bootAI | 24/6/2025 | 17/6/2026 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0. It has been classified as problematic. Affected is the function doLogin of the file /src/main/java/com/hope/controller/WebController.java of the component Login. The manipulation of the argument redirect_url leads to open redirect. It is possible to launch the… | |
| Analizada | Baja (2) | 0.45% | — | Java-aodeng Hope-boot | 24/6/2025 | 17/6/2026 | A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg leads to cross site scripting. The attack may be initiated remotely. The exploit has… | |
| Analizada | Alta (8.8) | 0.42% | — | Pbootcms | 18/6/2025 | 17/6/2026 | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request | |
| Aplazada | Baja (2.1) | 0.51% | — | Hansonwang99 Spring-boot-in-actionAI | 16/6/2025 | 17/6/2026 | A vulnerability was found in hansonwang99 Spring-Boot-In-Action up to 807fd37643aa774b94fd004cc3adbd29ca17e9aa. It has been declared as critical. Affected by this vulnerability is the function watermarkTest of the file /springbt_watermark/src/main/java/cn/codesheep/springbt_watermark/service/ImageUploadService.java of… | |
| Aplazada | Alta (7.7) | 4.0% | 💥 Exploit | JavaAIVmware Spring BootAI | 21/5/2025 | 17/6/2026 | OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive… | |
| Analizada | Media (4.8) | 0.41% | — | Moonlightl Hexo-boot | 21/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in moonlightL hexo-boot 4.3.0. This vulnerability affects unknown code of the file /admin/home/index.html of the component Dynamic List Page. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (4.8) | 0.41% | — | Moonlightl Hexo-boot | 21/5/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in moonlightL hexo-boot 4.3.0. This affects an unknown part of the file /admin/home/index.html of the component Blog Backend. The manipulation of the argument Description leads to cross site scripting. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.4) | 0.31% | — | Mohsinrasool Twitter Bootstrap Collapse AKA Accordian Shortcode | 15/5/2025 | 17/6/2026 | The Twitter Bootstrap Collapse aka Accordian Shortcode WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting… | |
| Aplazada | Media (5.6) | 0.32% | — | Getbootstrap BootstrapAI | 15/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap allows Cross-Site Scripting (XSS).This issue affects Bootstrap: from 3.4.1 before 4.0.0. | |
| Aplazada | Alta (7.1) | 0.16% | — | Intel Slim BootloaderAI | 13/5/2025 | 17/6/2026 | Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.1) | 0.44% | 💥 Exploit | Davidstutz Bootstrap Multiselect | 13/5/2025 | 17/6/2026 | An issue was discovered in post.php in bootstrap-multiselect (aka Bootstrap Multiselect) 1.1.2. A PHP script in the source code echoes arbitrary POST data. If a developer adopts this structure wholesale in a live application, it could create a Reflective Cross-Site Scripting (XSS) vulnerability exploitable through… | |
| Analizada | Media (5.1) | 0.79% | — | Jeecg Boot | 11/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the argument File leads to resource consumption. The attack can be… | |
| Aplazada | Media (5.3) | 0.57% | — | Vector4wang Spring-boot-quickAI | 10/5/2025 | 17/6/2026 | A vulnerability was found in vector4wang spring-boot-quick up to 20250422. It has been rated as critical. This issue affects the function ResponseEntity of the file /spring-boot-quick-master/quick-img2txt/src/main/java/com/quick/controller/Img2TxtController.java of the component quick-img2txt. The manipulation leads… | |
| Analizada | Media (6.5) | 0.36% | — | Huangjian888 Jeeweb-mybatis-springboot | 5/5/2025 | 17/6/2026 | Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload. | |
| Analizada | Crítica (9.8) | 0.53% | — | Java-aodeng Hope-boot | 5/5/2025 | 17/6/2026 | Incorrect access control in the /user/edit/ component of hope-boot v1.0.0 allows attackers to bypass authentication via a crafted GET request. | |
| Aplazada | Media (5.3) | 0.57% | — | Alanbinu007 Spring-boot-advanced-projectsAI | 1/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uploadUserProfileImage of the file /Spring-Boot-Advanced-Projects-main/Project-4.SpringBoot-AWS-S3/backend/src/main/java/com/urunov/profile/UserProfileController.java of the… | |
| Analizada | Media (6.1) | 0.27% | — | Thecartpress Boot Store | 28/4/2025 | 17/6/2026 | The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. | |
| Aplazada | Alta (7.3) | 0.43% | 💥 PoC | Vmware SecurityAIVmware BootAI | 28/4/2025 | 17/6/2026 | EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be affected by this if all the following conditions are met: You are not affected if any of the following is true: | |
| Analizada | Media (5.3) | 0.52% | — | Opplus Springboot-admin | 27/4/2025 | 17/6/2026 | A vulnerability was found in opplus springboot-admin 1.0 and classified as critical. This issue affects some unknown processing of the file \src\main\resources\mapper\sys\SysLogDao.xml. The manipulation of the argument order leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (6.1) | 0.24% | — | Bootstrap Site Alert Project Bootstrap Site Alert | 23/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Bootstrap Site Alert allows Cross-Site Scripting (XSS).This issue affects Bootstrap Site Alert: from 0.0.0 before 1.13.0, from 3.0.0 before 3.0.4. | |
| Analizada | Media (6.3) | 0.61% | — | Yxj2018 Springboot-vue-onlineexam | 22/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This issue affects some unknown processing of the component API. The manipulation leads to improper authentication. The attack may be initiated remotely. The complexity of an attack is rather high. The… | |
| Analizada | Media (5.3) | 0.37% | — | Yxj2018 Springboot-vue-onlineexam | 22/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in YXJ2018 SpringBoot-Vue-OnlineExam 1.0. This vulnerability affects unknown code of the file /api/studentPWD. The manipulation of the argument studentId leads to unverified password change. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.1) | 0.46% | — | Pbootcms | 18/4/2025 | 17/6/2026 | A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (4.8) | 0.58% | — | Oracle Graalvm FOR JDKOracle JDKOracle JRENetapp Bootstrap OS | 15/4/2025 | 17/6/2026 | Vulnerability in Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle Java SE: 21.0.6, 24; Oracle GraalVM for JDK: 21.0.6 and 24. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful… |