Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.35% | — | Jeecg Boot | 19/12/2025 | 5/10/2026 | A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the component Multi-Tenant Management Module. Performing manipulation of… | |
| Aplazada | Media (6.4) | 0.31% | — | Bootstrapped WP Recipe MakerAI | 17/12/2025 | 17/6/2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 10.2.3 due to insufficient input sanitization and output escaping on user-supplied attributes in the wprm-recipe-roundup-item shortcode. This makes it possible for… | |
| Analizada | Alta (7.6) | 0.27% | — | Denx U-boot | 10/12/2025 | 17/6/2026 | Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qualcomm chips IPQ4019, IPQ5018, IPQ5322, IPQ6018, IPQ8064, IPQ8074, and IPQ9574 could allow an attacker to execute arbitrary code. | |
| Analizada | Alta (7.3) | 0.29% | — | Yzcheng90 X-springboot | 4/12/2025 | 17/6/2026 | This vulnerability fundamentally arises from yzcheng90 X-SpringBoot 6.0's implementation of role-based access control (RBAC) through dual dependency on frontend menu systems and backend permission tables, without enforcing atomic synchronization between these components. The critical flaw manifests when frontend menu… | |
| Aplazada | Baja (2.9) | 0.37% | — | Nutzam NutzbootAINutzam NutzcloudAI | 1/12/2025 | 3/9/2026 | A weakness has been identified in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This affects the function getInputStream of the file nutzcloud/nutzcloud-literpc/src/main/java/org/nutz/boot/starter/literpc/impl/endpoint/http/HttpServletRpcEndpoint.java of the component LiteRpc-Serializer. Executing a manipulation can lead to… | |
| Analizada | Media (5.5) | 0.47% | — | Nutzam Nutzboot | 1/12/2025 | 25/9/2026 | A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Transaction API. The manipulation of the argument… | |
| Aplazada | Baja (2.1) | 0.26% | — | Nutzam NutzbootAI | 1/12/2025 | 25/9/2026 | A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Ethereum Wallet Handler. Performing a manipulation… | |
| Analizada | Alta (7.5) | 0.34% | — | Youlai-boot | 26/11/2025 | 17/6/2026 | Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users. | |
| Analizada | Crítica (9.8) | 0.42% | — | Youlai-boot | 26/11/2025 | 17/6/2026 | Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend. | |
| Aplazada | Media (6.4) | 0.18% | — | Shortcodes BootstrapAI | 21/11/2025 | 17/6/2026 | The Shortcodes Bootstrap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the [notification] shortcode in all versions up to, and including, 1.1. This is due to missing input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.11% | — | Intel Slim BootloaderAI | 11/11/2025 | 17/6/2026 | Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack… | |
| Aplazada | Media (5.4) | 0.10% | — | Intel ONE Boot Flash UpdateAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel ONE Boot Flash UpdateAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.… | |
| Aplazada | Media (6.4) | 0.27% | — | WP Bootstrap TabsAI | 11/11/2025 | 17/6/2026 | The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bootstrap_tab' shortcode in all versions up to, and including, 1.0.4. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.24% | — | Bootstrapped Visual Link PreviewAI | 5/11/2025 | 17/6/2026 | The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-preview shortcode in versions up to, and including, 2.2.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.4) | 0.23% | — | Bootstrap Multi Language Responsive PortfolioAI | 4/11/2025 | 17/6/2026 | The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level… | |
| Aplazada | Baja (2.1) | 0.38% | — | Jeecgboot Jeewx-bootAI | 3/11/2025 | 17/6/2026 | A security flaw has been discovered in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This affects the function getImgUrl of the file WxActGoldeneggsPrizesController.java. Performing manipulation of the argument imgurl results in path traversal. Remote exploitation of the attack is possible. The… | |
| Aplazada | Alta (7.5) | 0.26% | — | Blog-vue-springbootAI | 28/10/2025 | 17/6/2026 | Unauthorized modification of arbitrary articles vulnerability exists in blog-vue-springboot. | |
| Aplazada | Media (5.3) | 0.30% | — | Bootstrapped WP Recipe MakerAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brecht WP Recipe Maker wp-recipe-maker allows Code Injection.This issue affects WP Recipe Maker: from n/a through < 10.1.0. | |
| Aplazada | Media (6.4) | 0.23% | — | Epic Bootstrap ButtonsAI | 3/10/2025 | 17/6/2026 | The Epic Bootstrap Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘icol’ parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Analizada | Media (6.3) | 0.26% | — | Jeecg Boot | 1/10/2025 | 17/6/2026 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server. | |
| Analizada | Media (6.3) | 0.26% | — | Jeecg Boot | 1/10/2025 | 17/6/2026 | Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server. | |
| Aplazada | Alta (8.1) | 0.69% | — | Tiny Bootstrap Elements LightAI | 30/9/2025 | 17/6/2026 | The Tiny Bootstrap Elements Light plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.3.34 via the 'language' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 26/9/2025 | 17/6/2026 | A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but… | |
| Analizada | Baja (2.1) | 0.41% | — | Jeecg Boot | 26/9/2025 | 17/6/2026 | A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted… |