Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)0.53%—Aitangbao Springboot-manager11/3/202517/6/2026
A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unknown code of the file /sys/dept. The manipulation of the argument name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (4.8)0.53%—Aitangbao Springboot-manager11/3/202517/6/2026
A vulnerability classified as problematic has been found in aitangbao springboot-manager 3.0. This affects an unknown part of the file /sys/permission. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…
AplazadaBaja (3.2)0.36%—Tangem SDKAI8/3/202517/6/2026
operations/attestation/AttestationTask.kt in the Tangem SDK before 5.18.3 for Android has a logic flow in offline wallet attestation (genuineness check) that causes verification results to be disregarded during the first scan of a card. Exploitation may not have been possible.
AnalizadaMedia (6.1)0.28%—Tangiblewp Listivo13/2/202517/6/2026
The Listivo - Classified Ads WordPress Theme theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 2.3.67 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.9)0.45%—Wisi Tangram Gt31AI27/12/202417/6/2026
A vulnerability was found in WISI Tangram GT31 up to 20241214 and classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Request Handler. The manipulation leads to server-side request forgery. The attack may be launched remotely. The vendor was contacted early about this…
AplazadaCrítica (9.1)0.56%—Netangular Technologies Chatnet AIAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaAlta (7.1)0.30%—Tangible Loops AND LogicAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Reflected XSS.This issue affects Loops & Logic: from n/a through <= 4.1.4.
ModificadaMedia (5.4)0.42%—Aitangbao Springboot-manager1/2/202417/6/2026
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role.
ModificadaMedia (5.4)0.39%—Aitangbao Springboot-manager1/2/202417/6/2026
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add.
ModificadaMedia (5.4)0.40%—Aitangbao Springboot-manager1/2/202417/6/2026
springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user.
ModificadaMedia (5.4)0.42%—Aitangbao Springboot-manager1/2/202417/6/2026
springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded files.
ModificadaCrítica (9.8)0.68%—Tangyh Lamp-cloud2/11/202317/6/2026
Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.
ModificadaAlta (8.8)0.21%—Chetangole Smooth Scroll Links22/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole Smooth Scroll Links [SSL] plugin <= 1.1.0 versions.
ModificadaAlta (8.8)0.26%—Chetangole Wp-copyprotect [protect Your Blog Posts]4/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Chetan Gole WP-CopyProtect [Protect your blog posts] plugin <= 3.1.0 versions.
ModificadaMedia (5.3)0.57%—Tang Project TangFedoraproject FedoraRedhat Enterprise Linux11/7/202317/6/2026
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
ModificadaAlta (7.2)0.81%—Guantang Equipment Management System Project Guantang Equipment Management System28/6/202317/6/2026
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
ModificadaMedia (6.1)0.50%—Textangular21/2/202317/6/2026
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
ModificadaAlta (7.5)1.8%—Untangle Project Untangle26/7/202217/6/2026
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
ModificadaAlta (7.5)1.7%—Untangle Project Untangle26/7/202217/6/2026
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
ModificadaCrítica (9.8)1.6%—Pycrowdtangle Project Pycrowdtangle22/7/202217/6/2026
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
ModificadaAlta (7.5)1.6%—Tang Project Tang2/3/202217/6/2026
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
ModificadaMedia (5.3)0.90%—Tangro Business Workflow18/12/202017/6/2026
In tangro Business Workflow before 1.18.1, knowing an attachment ID, it is possible to download workitem attachments without being authenticated.
ModificadaMedia (4.3)0.65%—Tangro Business Workflow18/12/202017/6/2026
In tangro Business Workflow before 1.18.1, a user's profile contains some items that are greyed out and thus are not intended to be edited by regular users. However, this restriction is only applied client-side. Manipulating any of the greyed-out values in requests to /api/profile is not prohibited server-side.
ModificadaMedia (4.3)0.75%—Tangro Business Workflow18/12/202017/6/2026
An issue was discovered in tangro Business Workflow before 1.18.1. No (or broken) access control checks exist on the /api/document/<DocumentID>/attachments API endpoint. Knowing a document ID, an attacker can list all the attachments of a workitem, including their respective IDs. This allows the attacker to gather…
ModificadaMedia (6.5)0.67%—Tangro Business Workflow18/12/202017/6/2026
In tangro Business Workflow before 1.18.1, an attacker can manipulate the value of PERSON in requests to /api/profile in order to change profile information of other users.
Orbitaley — Vulnerabilidades