Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the component Filter Handler. The manipulation results in improper authorization. The attack may be performed from remote. The exploit has been released to the public and may be… | |
| Analizada | Baja (1.3) | 0.39% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the argument ids leads to improper authorization. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is… | |
| Analizada | Baja (1.3) | 0.38% | — | Jeecg Boot | 25/9/2025 | 17/6/2026 | A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing manipulation of the argument departId can lead to improper authorization. The attack can be executed remotely. This attack is characterized by high complexity. The… | |
| Analizada | Baja (2.1) | 0.40% | — | Jeecg Boot | 19/9/2025 | 17/6/2026 | A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. The vendor… | |
| Aplazada | Crítica (10) | 3.5% | 💥 Exploit | Vmware Cloud GatewayAIVmware BootAIVmware WebfluxAI | 16/9/2025 | 17/6/2026 | Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: | |
| Analizada | Baja (2.1) | 0.33% | — | Jeecg Boot | 12/9/2025 | 17/6/2026 | A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been released to the public… | |
| Analizada | Baja (2.1) | 0.44% | — | Jeecg Boot | 12/9/2025 | 17/6/2026 | A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to improper authorization. The attack can be initiated remotely. The… | |
| Modificada | Alta (7.5) | 2.3% | 💥 PoC | Redhat Build OF Apache Camel FOR Spring BootRedhat FuseRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Expansion Pack+4 | 2/9/2025 | 6/10/2026 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol… | |
| Aplazada | Alta (7.8) | 0.35% | 💥 PoC | BootromAI | 1/9/2025 | 17/6/2026 | In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privilege with no additional execution privileges needed. | |
| Aplazada | Media (6.5) | 0.24% | — | Areoi ALL Bootstrap BlocksAI | 28/8/2025 | 25/9/2026 | Missing Authorization vulnerability in all_bootstrap_blocks All Bootstrap Blocks all-bootstrap-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All Bootstrap Blocks: from n/a through <= 1.3.28. | |
| Aplazada | Alta (7.5) | 0.36% | — | SpringbootblogAI | 22/8/2025 | 17/6/2026 | Incorrect access control in the preHandle function of SpringBootBlog v1.0.0 allows attackers to access sensitive components without authentication. | |
| Analizada | Media (6.5) | 0.24% | — | Guojusoft Jeecgboot | 22/8/2025 | 17/6/2026 | JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Jeewx-bootAI | 20/8/2025 | 17/6/2026 | jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function | |
| Aplazada | Media (5.5) | 0.37% | — | Zlt2000 Microservices-platformAIVmware Spring BootAI | 8/8/2025 | 17/6/2026 | A vulnerability has been found in zlt2000 microservices-platform up to 6.0.0 and classified as problematic. This vulnerability affects unknown code of the file /actuator of the component Spring Actuator Interface. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (6.5) | 0.33% | 💥 PoC | Denx U-boot | 5/8/2025 | 17/6/2026 | A lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install crafted firmware files, leading to arbitrary code execution. | |
| Analizada | Baja (2.9) | 0.31% | — | Exrick Xboot | 4/8/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation leads to cleartext storage of sensitive information in a cookie. It is possible to launch the attack remotely. The complexity of an attack is… | |
| Analizada | Baja (2.1) | 0.33% | — | Exrick Xboot | 4/8/2025 | 17/6/2026 | A vulnerability was found in Exrick xboot up to 3.3.4. It has been rated as critical. This issue affects some unknown processing of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/SecurityController.java of the component Swagger. The manipulation of the argument loginUrl leads to… | |
| Analizada | Baja (2.1) | 0.34% | — | Exrick Xboot | 4/8/2025 | 17/6/2026 | A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the function Upload of the file xboot-fast/src/main/java/cn/exrick/xboot/modules/base/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The… | |
| Analizada | Media (5.5) | 0.45% | — | Exrick Xboot | 4/8/2025 | 17/6/2026 | A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Boot Admin/Spring Actuator. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Alta (8.6) | 0.45% | — | Trustedfirmware Trusted Firmware-mAIARM McubootAI | 30/7/2025 | 17/6/2026 | TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 lacks length validation during a firmware upgrade. While processing a new image, the Firmware Upgrade (FWU) module does not validate the length field of the Type-Length-Value (TLV) structure for dependent components… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Nbcio-bootAI | 17/7/2025 | 17/6/2026 | nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteRecycleBin. | |
| Aplazada | Baja (2.1) | 0.40% | — | Joeybling Springboot MybatisplusAI | 12/7/2025 | 17/6/2026 | A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. The manipulation of the argument Name leads to path traversal. The attack can be initiated remotely.… | |
| Aplazada | Baja (2.1) | 0.27% | — | Joeybling Springboot MybatisplusAI | 12/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The manipulation of the argument portraitFile leads to unrestricted upload. It is possible to initiate… | |
| Aplazada | Media (5.3) | 0.34% | — | ZipkinAIVmware Spring Boot ActuatorAI | 4/7/2025 | 17/6/2026 | Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927. |