Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
2109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.36% | — | Maliangnansheng Bbs-springbootAI | 13/9/2026 | 16/9/2026 | A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. | |
| Pendiente de análisis | Alta (8.1) | 0.59% | — | Siam OrderingAI | 9/9/2026 | 14/9/2026 | Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator. | |
| Aplazada | Alta (8.8) | 0.51% | — | Siam Ordering Siam-serverAI | 9/9/2026 | 10/9/2026 | A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and MemberWithdrawRecordMapper.java). | |
| Analizada | Alta (8.1) | 0.69% | — | Microsoft Spring Cloud | 8/9/2026 | 29/9/2026 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Crítica (9.1) | 0.51% | — | Springboot-projectAI | 8/9/2026 | 9/9/2026 | Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication. | |
| Pendiente de análisis | Media (6.5) | 0.25% | — | SAP Manufacturing Integration AND IntelligenceAI | 8/9/2026 | 8/9/2026 | Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed by the application, this behavior could be combined with XML/XSL processing to enable execution of scripts. Successful… | |
| Aplazada | Baja (2.1) | 0.45% | — | Sfturing SSM PROAI | 7/9/2026 | 28/9/2026 | A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. This manipulation of the argument hospitalName/officesName/doctorName causes cross site… | |
| Aplazada | Media (5.5) | 0.56% | — | Sfturing Hosp OrderAI | 7/9/2026 | 28/9/2026 | A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in… | |
| Aplazada | Media (5.5) | 0.56% | — | Sfturing Hosp OrderAI | 7/9/2026 | 28/9/2026 | A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Handler. The manipulation of the argument… | |
| Aplazada | Media (5.5) | 0.56% | — | Sfturing Hosp OrderAI | 7/9/2026 | 28/9/2026 | A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of the argument userIdenf can lead to… | |
| Aplazada | Media (5.5) | 0.60% | — | Sfturing Hosp OrderAI | 7/9/2026 | 28/9/2026 | A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery. Performing a manipulation results in unverified… | |
| Aplazada | Media (5.3) | 0.16% | — | Restaurant Menu AND Food OrderingAI | 4/9/2026 | 8/9/2026 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthenticated attackers to forge a payment notification and mark their own order as paid and completed without making any payment. | |
| Aplazada | Alta (8.9) | 0.47% | — | Eclipse ArrowheadAIApache TomcatAIVmware Spring MVCAIVmware Spring SecurityAI | 3/9/2026 | 3/9/2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on… | |
| Aplazada | Alta (7.1) | 0.18% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button.… | |
| Aplazada | Media (6.8) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 2/9/2026 | 3/9/2026 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts… | |
| Aplazada | Crítica (9.3) | 0.16% | — | Colorful IgamecenterAIWinring0x64AI | 31/8/2026 | 31/8/2026 | A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a… | |
| Aplazada | Baja (1.3) | 0.31% | — | Lognet Grpc-spring-boot-starterAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability… | |
| Aplazada | Alta (8.6) | 0.53% | — | Bladex SpringbladeAI | 28/8/2026 | 16/9/2026 | SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without… | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | ZipkinAIVmware Spring BootAI | 28/8/2026 | 24/9/2026 | Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress… | |
| Analizada | Alta (8.2) | 0.28% | — | Vmware Spring Integration | 27/8/2026 | 1/9/2026 | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message… | |
| Analizada | Media (6.3) | 0.29% | — | Vmware Spring Integration | 27/8/2026 | 1/9/2026 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering… | |
| Analizada | Media (5.4) | 0.18% | — | Vmware Spring Integration | 27/8/2026 | 31/8/2026 | A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, potentially leaking one message's payload/headers bindings into another… | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring Advanced Message Queuing Protocol | 27/8/2026 | 31/8/2026 | When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages the receiver's credit reaches zero and the broker stops delivering, leaving the listener silently… | |
| Analizada | Media (4.3) | 0.30% | — | Vmware Spring AI | 27/8/2026 | 31/8/2026 | RedisChatMemoryRepository.findByMetadata() builds RediSearch tag and text queries from caller-supplied metadata values without applying RediSearchUtil.escape(), unlike get(), clear(), and findByTimeRange() in the same class which do escape their inputs. An application that passes user-controlled values to… | |
| Analizada | Media (6.5) | 0.42% | — | Vmware Spring FOR Apache Kafka | 27/8/2026 | 4/9/2026 | DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0… |