Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.52% | — | Zoneland O2oa | 27/8/2025 | 17/6/2026 | O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function. | |
| Analizada | Media (6.1) | 0.28% | — | Zoneland O2oa | 31/1/2025 | 17/6/2026 | O2OA 9.1.3 is vulnerable to Cross Site Scripting (XSS) in Meetings - Settings. | |
| Analizada | Media (5.4) | 0.43% | — | Zoneland O2oa | 24/5/2024 | 17/6/2026 | An arbitrary file upload vulnerability in O2OA v8.3.8 allows attackers to execute arbitrary code via uploading a crafted PDF file. | |
| Analizada | Media (5.9) | 0.89% | — | Zoneland O2oa | 12/4/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3. The manipulation leads to information disclosure. It is possible to launch the attack… | |
| Modificada | Crítica (9.8) | 1.5% | — | Zoneland O2oa | 30/11/2023 | 17/6/2026 | Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript. | |
| Modificada | Crítica (9.8) | 39% | — | Zoneland O2oa | 17/2/2022 | 9/7/2026 | O2OA v6.4.7 was discovered to contain a remote code execution (RCE) vulnerability via /x_program_center/jaxrs/invoke. |