Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.15% | — | Cloverhackycolor CloverhbootloaderAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Read vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerability is associated with program files regparse.C. This issue affects CloverBootloader: before 5162. | |
| Aplazada | Media (5.1) | 0.15% | — | Cloverhackycolor CloverbootloaderAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in CloverHackyColor CloverBootloader (MdeModulePkg/Universal/RegularExpressionDxe/Oniguruma modules). This vulnerability is associated with program files regcomp.C. This issue affects CloverBootloader: before 5162. | |
| Aplazada | Baja (2) | 0.26% | — | Lcg0124 BootdoAI | 25/1/2026 | 17/6/2026 | A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulnerability is the function redirectToLogin of the file AccessControlFilter.java of the component Host Header Handler. This manipulation of the argument Hostname causes open redirect. The attack may be… | |
| Aplazada | Media (4.3) | 0.26% | — | Upress Booter Booter-bots-crawlers-managerAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in uPress Booter booter-bots-crawlers-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booter: from n/a through <= 1.5.7. | |
| Aplazada | Media (4.3) | 0.19% | — | Bootstrapped WP Recipe MakerAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Brecht WP Recipe Maker wp-recipe-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Recipe Maker: from n/a through <= 10.2.4. | |
| Aplazada | Baja (2) | 0.28% | — | Lcg0124 BootdoAI | 19/1/2026 | 17/6/2026 | A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This manipulation of the argument content/author/title causes cross site scripting. Remote exploitation of the attack is… | |
| Aplazada | Alta (8.5) | 0.16% | — | Bootp TurboAI | 16/1/2026 | 17/6/2026 | BOOTP Turbo 2.0.0.1253 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path to execute arbitrary code with elevated LocalSystem privileges during system startup or reboot. | |
| Aplazada | Media (4.3) | 0.35% | — | Bootstrapped WP Recipe MakerAI | 16/1/2026 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 10.2.2 via the api_get_post_summary function due to insufficient restrictions on which posts can be retrieved. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (4.6) | 0.17% | 💥 PoC | Airth Smart Home AQI Monitor Bootloader | 14/1/2026 | 5/7/2026 | An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive information via the UART port of the BK7231N controller (Wi-Fi and BLE module) on the device is open to access | |
| Aplazada | Media (6.5) | 0.19% | — | Neilgee Bootstrap ModalsAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in neilgee Bootstrap Modals bootstrap-modals allows Stored XSS.This issue affects Bootstrap Modals: from n/a through <= 1.3.2. | |
| Analizada | Media (5.5) | 0.25% | — | Pbootcms | 28/12/2025 | 17/6/2026 | A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The attack can be initiated remotely. The… | |
| Modificada | Baja (2.9) | 0.51% | — | Pbootcms | 28/12/2025 | 17/6/2026 | A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The… | |
| Analizada | Baja (1.3) | 0.39% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated remotely. The complexity of an attack is… | |
| Analizada | Baja (1.3) | 0.31% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. The attack can be launched remotely. This attack is characterized by high… | |
| Analizada | Baja (1.3) | 0.31% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The exploitability is… | |
| Analizada | Baja (1.3) | 0.31% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is… | |
| Analizada | Baja (1.3) | 0.31% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId results in improper authorization. It is possible to initiate the attack remotely. The attack is considered to have… | |
| Analizada | Media (4.8) | 0.41% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vendor was contacted early about this disclosure but did not respond in… | |
| Analizada | Baja (1.3) | 0.33% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The… | |
| Analizada | Baja (1.3) | 0.28% | — | Jeecg Boot | 28/12/2025 | 17/6/2026 | A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. A high complexity level is associated with this attack. The… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Synaccess NetbooterAI | 24/12/2025 | 17/6/2026 | Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain… | |
| Aplazada | Media (5.1) | 0.17% | — | Synaccess Netbooter Np-0801duAI | 24/12/2025 | 17/6/2026 | Synaccess netBooter NP-0801DU 7.4 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without proper request validation. Attackers can craft malicious web pages with hidden form submissions to add admin users by tricking authenticated administrators into loading… | |
| Analizada | Alta (7.1) | 0.32% | — | Youlai-boot | 22/12/2025 | 17/6/2026 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability. | |
| Analizada | Alta (7.5) | 0.44% | — | Youlai-boot | 22/12/2025 | 17/6/2026 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles. | |
| Analizada | Baja (2.1) | 0.51% | — | Jeecg Boot | 19/12/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The… |