Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

118 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.2%—Jflyfox Jfinal CMS5/5/202217/6/2026
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
ModificadaAlta (7.2)0.96%—Jflyfox Jfinal CMS3/5/202217/6/2026
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
ModificadaCrítica (9.8)1.2%—Jfinalcms Project Jfinalcms22/4/202217/6/2026
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
ModificadaMedia (5.4)0.49%—Jflyfox Jfinal CMS11/4/202217/6/2026
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
ModificadaMedia (6.5)1.1%—Jfinaloa Project Jfinaloa30/3/202217/6/2026
An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController.
ModificadaMedia (5.4)0.50%—Jflyfox Jfinal CMS25/1/202217/6/2026
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.
ModificadaAlta (7.5)1.0%—Jflyfox Jfinal CMS16/12/202117/6/2026
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
ModificadaAlta (7.5)1.2%—Jflyfox Jfinal CMS15/9/20219/7/2026
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
ModificadaAlta (8.8)7.5%—Jflyfox Jfinal CMS15/9/202117/6/2026
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
ModificadaMedia (6.5)3.9%—Jflyfox Jfinal CMS15/9/202117/6/2026
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
ModificadaAlta (8.8)5.0%—Jflyfox Jfinal CMS15/9/202117/6/2026
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
ModificadaAlta (8.1)3.5%—Jflyfox Jfinal CMS15/9/202117/6/2026
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
ModificadaMedia (5.4)1.1%—Jflyfox Jfinal CMS15/9/202117/6/2026
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.
ModificadaMedia (6.5)1.6%—Jflyfox Jfinal CMS15/9/202117/6/2026
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
ModificadaMedia (6.5)1.9%—Jflyfox Jfinal CMS15/9/202117/6/2026
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
ModificadaCrítica (9.8)1.8%—Jfinal24/6/202117/6/2026
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
ModificadaMedia (6.1)0.64%—Jfinal24/6/202117/6/2026
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.
ModificadaAlta (7.5)1.7%—Jfinal8/10/201917/6/2026
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.