Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.29% | — | Ruoyi-vue | 11/5/2025 | 17/6/2026 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue of the component Password Handler. The manipulation leads to cleartext storage of sensitive information in a… | |
| Analizada | Media (5.3) | 0.73% | — | Iocoder Ruoyi-vue-pro | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. It is possible to launch the… | |
| Analizada | Media (5.3) | 0.87% | — | Iocoder Ruoyi-vue-pro | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack… | |
| Analizada | Media (5.3) | 0.87% | — | Iocoder Ruoyi-vue-pro | 25/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack can be initiated… | |
| Analizada | Media (5.3) | 0.92% | — | Iocoder Ruoyi-vue-pro | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component Backend File Upload Interface. The manipulation of the argument path leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Media (5.3) | 0.92% | — | Iocoder Ruoyi-vue-pro | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload of the component Front-End Store Interface. The manipulation of the argument path leads to path traversal. The attack may… | |
| Analizada | Media (5.3) | 0.49% | — | Iocoder Ruoyi-vue-pro | 6/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.95% | — | Iocoder Ruoyi-vue-pro | 25/8/2022 | 17/6/2026 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. | |
| Modificada | Alta (7.3) | 2.2% | — | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 31/8/2017 | 17/6/2026 | An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the… | |
| Modificada | Alta (7.8) | 2.4% | 💥 Exploit | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2… | |
| Modificada | Alta (7) | 1.4% | 💥 Exploit | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An… | |
| Modificada | Media (6.3) | 8.5% | 💥 Exploit | Automatedlogic I-vuAutomatedlogic Sitescan WEBCarrier Automatedlogic Webctrl | 25/8/2017 | 17/6/2026 | A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker… |