Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.29%—Fengoffice Feng OfficeAI2/6/202517/6/2026
A vulnerability was found in Fengoffice Feng Office 3.5.1.5 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php?c=account&a=set_timezone. The manipulation of the argument tz_offset leads to sql injection. The attack may be launched remotely. The exploit has been…
AplazadaMedia (5.3)0.32%—Feng HA HA Megagao Ssm-erpAIMegagao Production SSMAI16/5/202517/6/2026
A vulnerability classified as critical has been found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. This affects the function uploadPicture of the file PictureServiceImpl.java. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has…
AplazadaMedia (5.3)0.47%—Feng HA HA Megagao Ssm-erpAIMegagao Production SSMAI11/5/202517/6/2026
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm 1.0. It has been declared as problematic. Affected by this vulnerability is the function handleFileDownload of the file FileController.java of the component File Handler. The manipulation leads to path traversal. The attack can be launched…
AplazadaMedia (5.3)0.33%—Feng HA HA Megagao Ssm-erpAIMegagao Production SSMAI6/5/202517/6/2026
A vulnerability was found in feng_ha_ha/megagao ssm-erp and production_ssm up to 0.0.1. It has been classified as critical. This affects the function uploadFile of the file src/main/java/com/megagao/production/ssm/service/impl/FileServiceImpl.java. The manipulation of the argument uploadFile leads to unrestricted…
AnalizadaCrítica (9.8)0.54%—Liaoxuefeng Itranswarp5/5/202517/6/2026
An issue in the component /manage/ of itranswarp v2.19 allows attackers to bypass authentication via a crafted request.
AnalizadaMedia (5.3)0.32%—Zhenfeng13 My-bbs19/4/202517/6/2026
A vulnerability has been found in zhenfeng13 My-BBS 1.0 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.
AnalizadaMedia (5.3)0.53%—Zhenfeng13 My-bbs19/4/202517/6/2026
A vulnerability, which was classified as critical, was found in zhenfeng13 My-BBS 1.0. This affects the function Upload of the file src/main/java/com/my/bbs/controller/common/UploadController.java of the component Endpoint. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely.…
AnalizadaMedia (5.3)0.56%—Zhenfeng13 My-blog-layui14/4/202517/6/2026
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerability affects the function Upload of the file /admin/upload/authorImg/. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.1)0.40%—Zhenfeng13 My-blog-layui14/4/202517/6/2026
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AnalizadaMedia (5.1)0.40%—Zhenfeng13 My-blog-layui14/4/202517/6/2026
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/blog/edit. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public…
AplazadaMedia (5.3)0.41%—TU Yafeng VIA BrowserAI27/2/202517/6/2026
A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown processing of the component Javascript Bridge. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public…
AplazadaMedia (5.5)0.19%—Yibin Fengguan Network Technology Yupao DirecthireAI27/2/202517/6/2026
An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaMedia (4.8)0.38%—Northern.tech Cfengine Enterprise Mission PortalAI21/1/202517/6/2026
Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.
AplazadaMedia (6.5)0.23%—Fengler Magic Google MapsAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fengler Magic Google Maps magic-google-maps allows Stored XSS.This issue affects Magic Google Maps: from n/a through <= 1.0.4.
AnalizadaMedia (5.3)0.43%—Zhenfeng13 My-blog6/1/202517/6/2026
A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uploadController. java. The manipulation of the argument file leads to unrestricted upload. The attack can be launched…
AnalizadaMedia (5.3)0.43%—Zhenfeng13 My-blog6/1/202517/6/2026
A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the argument editormd-image-file leads to unrestricted upload. It is possible to launch…
AnalizadaMedia (6.3)0.77%—Kaoshifeng Yunfan Learning Examination System2/1/202517/6/2026
A vulnerability classified as critical was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected by this vulnerability is an unknown functionality of the file src/main/java/com/yf/exam/modules/sys/user/controller/SysUserControl of the component JWT Token Handler. The…
AnalizadaMedia (5.3)0.62%—Kaoshifeng Yunfan Learning Examination System2/1/202517/6/2026
A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to…
AnalizadaMedia (6.9)0.57%—Kaoshifeng Yunfan Learning Examination System2/1/202517/6/2026
A vulnerability was found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. It has been rated as critical. This issue affects some unknown processing of the file /doc.html. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been…
ModificadaMedia (5.3)0.73%💥 ExploitFengoffice Feng Office16/6/202417/6/2026
A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaCrítica (9.8)1.6%—Fengjiachun Jupiter1/12/202317/6/2026
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
ModificadaAlta (7.5)0.65%—Northern.tech Cfengine14/11/202317/6/2026
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
ModificadaMedia (5.3)0.53%—Kaoshifeng Yunfan Learning Examination System4/11/202317/6/2026
An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.
AnalizadaMedia (5.4)0.36%—Zhenfeng13 MY Blog1/5/202317/6/2026
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via editing an article in the "blog article" page due to the default configuration not utilizing MyBlogUtils.cleanString.
AnalizadaMedia (5.4)0.41%—Zhenfeng13 MY Blog1/5/202317/6/2026
Cross site scripting (XSS) vulnerability in ZHENFENG13 My-Blog, allows attackers to inject arbitrary web script or HTML via the "title" field in the "blog management" page due to the the default configuration not using MyBlogUtils.cleanString.
Orbitaley — Vulnerabilidades