Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.27% | — | Bootstrapy CMSAI | 24/3/2026 | 17/6/2026 | Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can inject SQL payloads into the thread_id parameter of forum-thread.php, the subject parameter of contact-submit.php, the… | |
| Aplazada | Baja (2.1) | 0.35% | — | PbootcmsAI | 21/3/2026 | 17/6/2026 | A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The attack may be performed from remote. The… | |
| Aplazada | Baja (2.1) | 0.45% | — | PbootcmsAI | 21/3/2026 | 17/6/2026 | A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Baja (2.1) | 0.38% | — | PbootcmsAI | 21/3/2026 | 17/6/2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The exploit has been released to the public and… | |
| Aplazada | Media (5.5) | 0.41% | — | PbootcmsAI | 20/3/2026 | 17/6/2026 | A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit is… | |
| Analizada | Alta (8.1) | 0.36% | — | Vmware Spring Boot | 20/3/2026 | 17/6/2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11,… | |
| Analizada | Alta (8.1) | 0.33% | — | Vmware Spring Boot | 19/3/2026 | 17/6/2026 | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before… | |
| Aplazada | Baja (2.1) | 0.33% | — | JeecgbootAI | 7/3/2026 | 17/6/2026 | A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Media (5.3) | 0.26% | — | Bootstrapped WP Recipe MakerAI | 27/2/2026 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) in versions up to, and including, 10.3.2. This is due to the /wp-json/wp-recipe-maker/v1/integrations/instacart REST API endpoint's permission_callback being set to __return_true and a lack of subsequent authorization… | |
| Aplazada | Baja (2.3) | 0.35% | — | Szadmin Sz-boot-parentAI | 25/2/2026 | 17/6/2026 | A weakness has been identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This vulnerability affects unknown code of the file /api/admin/common/files/download. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be executed remotely. Attacks of this nature are… | |
| Aplazada | Baja (2.1) | 0.48% | — | Feiyuchuixue SZ Boot ParentAI | 25/2/2026 | 17/6/2026 | A security flaw has been discovered in feiyuchuixue sz-boot-parent up to 1.3.2-beta. This affects an unknown part of the file /api/admin/common/download/templates of the component API. Performing a manipulation of the argument templateName results in path traversal. Remote exploitation of the attack is possible. The… | |
| Analizada | Baja (2.1) | 0.53% | — | Szadmin Sz-boot-parent | 25/2/2026 | 17/6/2026 | A vulnerability was identified in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this issue is some unknown functionality of the file /api/admin/sys-file/upload of the component API Endpoint. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly… | |
| Analizada | Baja (2.1) | 0.36% | — | Szadmin Sz-boot-parent | 25/2/2026 | 17/6/2026 | A vulnerability was determined in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected by this vulnerability is an unknown functionality of the file /api/admin/sys-user/reset/password/ of the component Password Reset Handler. This manipulation of the argument userId causes use of default password. The attack may be… | |
| Analizada | Media (5.5) | 0.68% | — | Szadmin Sz-boot-parent | 25/2/2026 | 17/6/2026 | A vulnerability was found in feiyuchuixue sz-boot-parent up to 1.3.2-beta. Affected is an unknown function of the file /api/admin/sys-message/ of the component API Endpoint. The manipulation of the argument messageId results in authorization bypass. The attack can be launched remotely. The exploit has been made public… | |
| Aplazada | Alta (7) | 0.15% | — | Opensuse SdbootutilAI | 25/2/2026 | 17/6/2026 | This issue affects sdbootutil: from ? before 5880246d3a02642dc68f5c8cb474bf63cdb56bca. | |
| Aplazada | Media (4.3) | 0.23% | — | Bootstrapped WP Recipe MakerAI | 25/2/2026 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'ajax_search_recipes' and 'ajax_get_recipe' functions in all versions up to, and including, 10.2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 22/2/2026 | 17/6/2026 | A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been made available to… | |
| Aplazada | Media (5.3) | 0.45% | — | PhotoboothAI | 20/2/2026 | 17/6/2026 | Photobooth prior to 1.0.1 has a cross-site scripting (XSS) vulnerability in user input fields. Malicious users could inject scripts through unvalidated form inputs. This vulnerability is fixed in 1.0.1. | |
| Analizada | Baja (2.1) | 0.49% | — | Jeecg Boot | 20/2/2026 | 17/6/2026 | A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag_app,1,create_by of the component Backend Interface. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The… | |
| Analizada | Baja (2.3) | 0.59% | — | Jeecg Boot | 16/2/2026 | 17/6/2026 | A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generation. Executing a manipulation can lead to deserialization. The attack can be… | |
| Analizada | Baja (2.1) | 0.60% | — | Jeecg Boot | 7/2/2026 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument filePath can lead to path traversal. The attack can be executed remotely.… | |
| Aplazada | Baja (2.1) | 0.22% | — | Lcg0124 BootdoAI | 4/2/2026 | 17/6/2026 | A vulnerability was identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. This affects an unknown part. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This product adopts a rolling… | |
| Aplazada | Media (6.5) | 0.35% | — | Bootstrapped Visual Link PreviewAI | 3/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Brecht Visual Link Preview visual-link-preview allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visual Link Preview: from n/a through <= 2.2.9. | |
| Analizada | Baja (2.1) | 0.50% | — | Jeecg Boot | 2/2/2026 | 17/6/2026 | A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit is publicly available… | |
| Aplazada | Media (5.1) | 0.35% | — | BootcommerceAI | 1/2/2026 | 17/6/2026 | BootCommerce 3.2.1 contains persistent input validation vulnerabilities that allow remote attackers to inject malicious script code through guest order checkout input fields. Attackers can exploit unvalidated input parameters to execute arbitrary scripts, potentially leading to session hijacking, phishing attacks, and… |