Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.23%—Bladex SpringbladeAI24/9/202625/9/2026
A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId…
AplazadaAlta (8.6)0.53%—Bladex SpringbladeAI28/8/202616/9/2026
SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without…
AplazadaAlta (8.7)0.37%—Brave CMSAILaravel BladeAICkeditorAI8/5/202617/6/2026
Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is…
AplazadaAlta (8.8)0.60%—Bladex SpringbladeAI30/4/202617/6/2026
An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.
AplazadaMedia (6.1)0.33%—Bladex SpringbladeAI30/4/202617/6/2026
A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter.
AplazadaMedia (5)0.28%—Bladex SpringbladeAI30/4/202617/6/2026
A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.
Pendiente de análisisAlta (8.5)0.38%—Purestorage FlashbladeAI14/4/202617/6/2026
A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions.
AplazadaBaja (2.1)0.41%—Antaresmugisho PybladeAI5/4/202624/7/2026
A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipulation leads to improper neutralization of special elements used in a template engine. The attack may be performed from…
AnalizadaCrítica (9.9)0.34%—Bladex Springblade26/1/202617/6/2026
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
AnalizadaCrítica (9.9)0.41%—Bladex Springblade23/1/202617/6/2026
Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.
AplazadaAlta (8.3)0.33%—Purestorage FlashbladeAI10/6/202517/6/2026
Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service.
AplazadaAlta (8.6)1.7%—ChaosbladeAI18/9/202417/6/2026
exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.
AnalizadaMedia (5.3)0.64%—Bladex Springblade21/8/202417/6/2026
A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.…
AplazadaCrítica (9.3)0.38%—Purestorage FlashbladeAI17/7/202417/6/2026
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
AnalizadaAlta (7.5)0.68%—Bladex Springblade30/4/202417/6/2026
An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.
AnalizadaCrítica (9.8)0.70%—Shanghai Brad Technology Bladex Project Shanghai Brad Technology Bladex28/3/202417/6/2026
A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the component API. The manipulation with the input updatexml(1,concat(0x3f,md5(123456),0x3f),1)=1 leads to sql injection. It is possible to launch…
ModificadaCrítica (9.8)0.64%—Bladex Springblade2/1/20249/7/2026
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
ModificadaMedia (5.3)0.77%—Bladex Springblade19/9/202317/6/2026
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs
ModificadaCrítica (9.8)18%—Bladex Springblade29/8/202317/6/2026
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection.
ModificadaAlta (7.1)0.30%—ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+1330/5/202317/6/2026
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission.
ModificadaBaja (3.3)0.29%—ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+1330/5/202317/6/2026
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could start a non-public interface of an application without user permission.
ModificadaAlta (7.1)0.30%—ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+1330/5/202317/6/2026
There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission.
ModificadaCrítica (9.8)2.0%—Bladex Springblade5/5/202217/6/2026
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
ModificadaMedia (6.4)0.23%—Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+1414/10/202017/6/2026
A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected.
ModificadaMedia (6.1)0.67%—IBM Bladecenter Advanced Management Module Firmware15/9/202017/6/2026
A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web…