Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.23% | — | Bladex SpringbladeAI | 24/9/2026 | 25/9/2026 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId… | |
| Aplazada | Alta (8.6) | 0.53% | — | Bladex SpringbladeAI | 28/8/2026 | 16/9/2026 | SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed via @RestController without… | |
| Aplazada | Alta (8.7) | 0.37% | — | Brave CMSAILaravel BladeAICkeditorAI | 8/5/2026 | 17/6/2026 | Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with Laravel Blade's unescaped output directive {!! !!}. Any JavaScript or HTML injected by an editor-role user is… | |
| Aplazada | Alta (8.8) | 0.60% | — | Bladex SpringbladeAI | 30/4/2026 | 17/6/2026 | An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload. | |
| Aplazada | Media (6.1) | 0.33% | — | Bladex SpringbladeAI | 30/4/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the content parameter. | |
| Aplazada | Media (5) | 0.28% | — | Bladex SpringbladeAI | 30/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request. | |
| Pendiente de análisis | Alta (8.5) | 0.38% | — | Purestorage FlashbladeAI | 14/4/2026 | 17/6/2026 | A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions. | |
| Aplazada | Baja (2.1) | 0.41% | — | Antaresmugisho PybladeAI | 5/4/2026 | 24/7/2026 | A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipulation leads to improper neutralization of special elements used in a template engine. The attack may be performed from… | |
| Analizada | Crítica (9.9) | 0.34% | — | Bladex Springblade | 26/1/2026 | 17/6/2026 | Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data. | |
| Analizada | Crítica (9.9) | 0.41% | — | Bladex Springblade | 23/1/2026 | 17/6/2026 | Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. | |
| Aplazada | Alta (8.3) | 0.33% | — | Purestorage FlashbladeAI | 10/6/2025 | 17/6/2026 | Improper input validation performed during the authentication process of FlashBlade could lead to a system Denial of Service. | |
| Aplazada | Alta (8.6) | 1.7% | — | ChaosbladeAI | 18/9/2024 | 17/6/2026 | exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication. | |
| Analizada | Media (5.3) | 0.64% | — | Bladex Springblade | 21/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in chillzhuang SpringBlade 4.1.0. Affected is an unknown function of the file /api/blade-system/menu/list?updatexml. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Aplazada | Crítica (9.3) | 0.38% | — | Purestorage FlashbladeAI | 17/7/2024 | 17/6/2026 | A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array. | |
| Analizada | Alta (7.5) | 0.68% | — | Bladex Springblade | 30/4/2024 | 17/6/2026 | An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant. | |
| Analizada | Crítica (9.8) | 0.70% | — | Shanghai Brad Technology Bladex Project Shanghai Brad Technology Bladex | 28/3/2024 | 17/6/2026 | A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the component API. The manipulation with the input updatexml(1,concat(0x3f,md5(123456),0x3f),1)=1 leads to sql injection. It is possible to launch… | |
| Modificada | Crítica (9.8) | 0.64% | — | Bladex Springblade | 2/1/2024 | 9/7/2026 | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. | |
| Modificada | Media (5.3) | 0.77% | — | Bladex Springblade | 19/9/2023 | 17/6/2026 | SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs | |
| Modificada | Crítica (9.8) | 18% | — | Bladex Springblade | 29/8/2023 | 17/6/2026 | In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | |
| Modificada | Alta (7.1) | 0.30% | — | ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+13 | 30/5/2023 | 17/6/2026 | There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission. | |
| Modificada | Baja (3.3) | 0.29% | — | ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+13 | 30/5/2023 | 17/6/2026 | There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could start a non-public interface of an application without user permission. | |
| Modificada | Alta (7.1) | 0.30% | — | ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+13 | 30/5/2023 | 17/6/2026 | There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission. | |
| Modificada | Crítica (9.8) | 2.0% | — | Bladex Springblade | 5/5/2022 | 17/6/2026 | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. | |
| Modificada | Media (6.4) | 0.23% | — | Lenovo Bladecenter Hs23 FirmwareLenovo Bladecenter Hs23e FirmwareLenovo Compute Node-x440 FirmwareLenovo Flex System X220 Firmware+14 | 14/10/2020 | 17/6/2026 | A potential vulnerability in the SMI callback function used in the legacy BIOS mode USB drivers in some legacy Lenovo and IBM System x servers may allow arbitrary code execution. Servers operating in UEFI mode are not affected. | |
| Modificada | Media (6.1) | 0.67% | — | IBM Bladecenter Advanced Management Module Firmware | 15/9/2020 | 17/6/2026 | A cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interface prior to version 3.68n [BPET68N]. This vulnerability could allow an authenticated user's AMM credentials to be disclosed if the user is convinced to visit a malicious web… |