Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.51% | — | Jeecg Boot | 19/12/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The… | |
| Analizada | Baja (2.1) | 0.35% | — | Jeecg Boot | 19/12/2025 | 5/10/2026 | A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the component Multi-Tenant Management Module. Performing manipulation of… | |
| Aplazada | Baja (2.1) | 0.38% | — | Jeecgboot Jeewx-bootAI | 3/11/2025 | 17/6/2026 | A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the argument imgurl results in path traversal. Remote exploitation of the attack is possible. The… | |
| Analizada | Media (6.3) | 0.26% | — | Jeecg Boot | 1/10/2025 | 17/6/2026 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server. | |
| Analizada | Media (6.3) | 0.26% | — | Jeecg Boot | 1/10/2025 | 17/6/2026 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server. | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 26/9/2025 | 17/6/2026 | A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but… | |
| Analizada | Baja (2.1) | 0.41% | — | Jeecg Boot | 26/9/2025 | 17/6/2026 | A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the component Filter Handler. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been released to the public and may be… | |
| Analizada | Baja (1.3) | 0.39% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the argument ids leads to improper authorization. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is… | |
| Analizada | Baja (1.3) | 0.38% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing manipulation of the argument departId can lead to improper authorization. The attack can be executed remotely. This attack is characterized by high complexity. The… | |
| Analizada | Baja (2.1) | 0.61% | — | Jeecg Jimureport | 21/9/2025 | 17/6/2026 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed… | |
| Analizada | Baja (2.1) | 0.43% | — | Jeecg Jimureport | 21/9/2025 | 17/6/2026 | A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in deserialization. Remote exploitation of the attack is possible. The exploit has been made public and… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 19/9/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. The vendor… | |
| Analizada | Baja (2.1) | 0.33% | — | Jeecg Boot | 12/9/2025 | 17/6/2026 | A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been released to the public… | |
| Analizada | Baja (2.1) | 0.44% | — | Jeecg Boot | 12/9/2025 | 17/6/2026 | A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to improper authorization. The attack can be initiated remotely. The… | |
| Analizada | Media (6.5) | 0.24% | — | Guojusoft Jeecgboot | 22/8/2025 | 17/6/2026 | JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions. | |
| Analizada | Media (5.3) | 0.49% | — | Jeecg Jimureport | 14/8/2025 | 17/6/2026 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to… | |
| Analizada | Media (5.1) | 0.79% | — | Jeecg Boot | 11/5/2025 | 17/6/2026 | A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the argument File leads to resource consumption. The attack can be… | |
| Analizada | Alta (7.5) | 0.58% | — | Guojusoft Jeecgboot | 7/2/2025 | 17/6/2026 | SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component. | |
| Analizada | Crítica (9.8) | 44% | 💥 Exploit | Jeecg Boot | 31/10/2024 | 17/6/2026 | JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | |
| Analizada | Crítica (9.8) | 0.53% | — | Jeecg Jimureport | 10/9/2024 | 17/6/2026 | An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. | |
| Modificada | Crítica (9.8) | 39% | — | Jeecg | 3/1/2024 | 17/6/2026 | Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. | |
| Modificada | Crítica (9.8) | 2.7% | — | Jeecg Boot | 30/12/2023 | 17/6/2026 | SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component. | |
| Modificada | Crítica (9.8) | 0.93% | — | Jeecg Boot | 30/12/2023 | 17/6/2026 | SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check. |