Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.2% | — | Jflyfox Jfinal CMS | 5/5/2022 | 17/6/2026 | A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. | |
| Modificada | Alta (7.2) | 0.96% | — | Jflyfox Jfinal CMS | 3/5/2022 | 17/6/2026 | Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jfinalcms Project Jfinalcms | 22/4/2022 | 17/6/2026 | JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. | |
| Modificada | Media (5.4) | 0.49% | — | Jflyfox Jfinal CMS | 11/4/2022 | 17/6/2026 | Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it. | |
| Modificada | Media (6.5) | 1.1% | — | Jfinaloa Project Jfinaloa | 30/3/2022 | 17/6/2026 | An SQL Injection vulnerability exists in glorylion JFinalOA as of 9/7/2021 in the defkey parameter getHaveDoneTaskDataList method of the FlowTaskController. | |
| Modificada | Media (5.4) | 0.50% | — | Jflyfox Jfinal CMS | 25/1/2022 | 17/6/2026 | In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code. | |
| Modificada | Alta (7.5) | 1.0% | — | Jflyfox Jfinal CMS | 16/12/2021 | 17/6/2026 | JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. | |
| Modificada | Alta (7.5) | 1.2% | — | Jflyfox Jfinal CMS | 15/9/2021 | 9/7/2026 | Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js. | |
| Modificada | Alta (8.8) | 7.5% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'. | |
| Modificada | Media (6.5) | 3.9% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'. | |
| Modificada | Alta (8.8) | 5.0% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'. | |
| Modificada | Alta (8.1) | 3.5% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'. | |
| Modificada | Media (5.4) | 1.1% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'. | |
| Modificada | Media (6.5) | 1.6% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'. | |
| Modificada | Media (6.5) | 1.9% | — | Jflyfox Jfinal CMS | 15/9/2021 | 17/6/2026 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'. | |
| Modificada | Crítica (9.8) | 1.8% | — | Jfinal | 24/6/2021 | 17/6/2026 | In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute | |
| Modificada | Media (6.1) | 0.64% | — | Jfinal | 24/6/2021 | 17/6/2026 | An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases. | |
| Modificada | Alta (7.5) | 1.7% | — | Jfinal | 8/10/2019 | 17/6/2026 | In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions. |