Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.53% | — | Aitangbao Springboot-manager | 11/3/2025 | 17/6/2026 | A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unknown code of the file /sys/dept. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (4.8) | 0.53% | — | Aitangbao Springboot-manager | 11/3/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in aitangbao springboot-manager 3.0. This affects an unknown part of the file /sys/permission. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (3.2) | 0.36% | — | Tangem SDKAI | 8/3/2025 | 17/6/2026 | operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible. | |
| Analizada | Media (6.1) | 0.28% | — | Tangiblewp Listivo | 13/2/2025 | 17/6/2026 | The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 2.3.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.9) | 0.45% | — | Wisi Tangram Gt31AI | 27/12/2024 | 17/6/2026 | A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to server-side request forgery. The attack may be launched remotely. The vendor was contacted early about this… | |
| Aplazada | Crítica (9.1) | 0.56% | — | Netangular Technologies Chatnet AIAI | 24/10/2024 | 17/6/2026 | A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | |
| Aplazada | Alta (7.1) | 0.30% | — | Tangible Loops AND LogicAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Reflected XSS.This issue affects Loops & Logic: from n/a through <= 4.1.4. | |
| Modificada | Media (5.4) | 0.42% | — | Aitangbao Springboot-manager | 1/2/2024 | 17/6/2026 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role. | |
| Modificada | Media (5.4) | 0.39% | — | Aitangbao Springboot-manager | 1/2/2024 | 17/6/2026 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add. | |
| Modificada | Media (5.4) | 0.40% | — | Aitangbao Springboot-manager | 1/2/2024 | 17/6/2026 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user. | |
| Modificada | Media (5.4) | 0.42% | — | Aitangbao Springboot-manager | 1/2/2024 | 17/6/2026 | springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files. | |
| Modificada | Crítica (9.8) | 0.68% | — | Tangyh Lamp-cloud | 2/11/2023 | 17/6/2026 | Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token. | |
| Modificada | Alta (8.8) | 0.21% | — | Chetangole Smooth Scroll Links | 22/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Chetangole Wp-copyprotect [protect Your Blog Posts] | 4/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 versions. | |
| Modificada | Media (5.3) | 0.57% | — | Tang Project TangFedoraproject FedoraRedhat Enterprise Linux | 11/7/2023 | 17/6/2026 | A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host. | |
| Modificada | Alta (7.2) | 0.81% | — | Guantang Equipment Management System Project Guantang Equipment Management System | 28/6/2023 | 17/6/2026 | Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload. | |
| Modificada | Media (6.1) | 0.50% | — | Textangular | 21/2/2023 | 17/6/2026 | textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches. | |
| Modificada | Alta (7.5) | 1.8% | — | Untangle Project Untangle | 26/7/2022 | 17/6/2026 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running. | |
| Modificada | Alta (7.5) | 1.7% | — | Untangle Project Untangle | 26/7/2022 | 17/6/2026 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files. | |
| Modificada | Crítica (9.8) | 1.6% | — | Pycrowdtangle Project Pycrowdtangle | 22/7/2022 | 17/6/2026 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | |
| Modificada | Alta (7.5) | 1.6% | — | Tang Project Tang | 2/3/2022 | 17/6/2026 | A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys. | |
| Modificada | Media (5.3) | 0.90% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated. | |
| Modificada | Media (4.3) | 0.65% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipulating any of the greyed-out values in requests to /api/profile is not prohibited server-side. | |
| Modificada | Media (4.3) | 0.75% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather… | |
| Modificada | Media (6.5) | 0.67% | — | Tangro Business Workflow | 18/12/2020 | 17/6/2026 | In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users. |