Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.47% | — | 0215andrewfeng Ace-mcpAI | 20/9/2026 | 21/9/2026 | A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_snippet of the file getFileSnippet.ts of the component MCP Tool. Executing a manipulation of the argument projectRootPath/filePath can lead to path traversal. The attack may be launched remotely. The… | |
| Aplazada | Baja (2) | 0.35% | — | Liaoxuefeng ItranswarpAI | 14/9/2026 | 15/9/2026 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The… | |
| Aplazada | Baja (2) | 0.33% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 14/9/2026 | A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulation of the argument og_objects.name can lead to cross site scripting. The attack… | |
| Aplazada | Baja (2) | 0.33% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 16/9/2026 | A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handlers. Performing a manipulation of the argument modules/dims results in sql… | |
| Aplazada | Media (5.5) | 0.41% | — | Fengoffice Feng OfficeAI | 13/9/2026 | 14/9/2026 | A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of the argument auth leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.5) | 0.32% | — | Wolfssl Wolfengine | 28/8/2026 | 29/9/2026 | wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer instead of the TLS sequence number carried in the additional authenticated data. Because the record layer leaves the explicit-nonce field for the cipher to populate, the value read is constant… | |
| Analizada | Alta (7.4) | 0.38% | — | Wolfssl Wolfengine | 28/8/2026 | 29/9/2026 | wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream… | |
| Aplazada | Crítica (9.8) | 0.66% | — | Fengoffice Feng OfficeAI | 17/7/2026 | 23/7/2026 | An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory. | |
| Pendiente de análisis | Media (6.1) | 0.28% | — | Northern.tech Cfengine EnterpriseAI | 2/6/2026 | 22/7/2026 | Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. | |
| Analizada | Alta (7.3) | 0.92% | — | Northern.tech Cfengine | 14/5/2026 | 17/6/2026 | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. | |
| Analizada | Media (5.3) | 0.21% | — | Northern.tech Cfengine | 14/5/2026 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. | |
| Analizada | Media (6.1) | 0.17% | — | Northern.tech Cfengine | 14/5/2026 | 17/6/2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. | |
| Aplazada | Baja (2.1) | 0.46% | — | Feng HA HA Megagao Ssm-erpAIMegagao Production SSMAI | 21/2/2026 | 17/6/2026 | A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the function pictureDelete of the file PictureController.java. Such manipulation of the argument picName leads to path traversal. The attack can be launched remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.46% | — | Feng HA HA Megagao Ssm-erpAIMegagao Production SSMAI | 21/2/2026 | 17/6/2026 | A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the function deleteFile of the file FileServiceImpl.java. This manipulation causes path traversal. The attack can be initiated remotely. The exploit has been published and may… | |
| Aplazada | Baja (2.1) | 0.36% | — | Feng HA HA Megagao Ssm-erpAIMegagao Production SSMAI | 21/2/2026 | 17/6/2026 | A security vulnerability has been detected in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. Impacted is an unknown function of the file EmployeeController.java. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.29% | — | Bestfeng OA GIT FreeAI | 15/11/2025 | 17/6/2026 | A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\src\main\java\com\cloudweb\oa\controller\WorkflowPredefineController.java. This manipulation of the argument writeProp causes xml external entity reference. The attack is… | |
| Analizada | Media (6.5) | 0.26% | — | Bestfeng Xckk | 9/10/2025 | 17/6/2026 | In xckk v9.6, there is a SQL injection vulnerability in which the cond parameter in notice/list is not securely filtered, resulting in a SQL injection vulnerability. | |
| Analizada | Media (6.5) | 0.22% | — | Bestfeng Xckk | 9/10/2025 | 17/6/2026 | In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in address/list is not securely filtered, resulting in a SQL injection vulnerability. | |
| Analizada | Media (6.5) | 0.26% | — | Bestfeng Xckk | 9/10/2025 | 17/6/2026 | In xckk v9.6, there is a SQL injection vulnerability in which the orderBy parameter in user/list is not securely filtered, resulting in a SQL injection vulnerability. | |
| Analizada | Alta (8.6) | 0.32% | — | Liaoxuefeng Itranswarp | 20/8/2025 | 17/6/2026 | Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication. | |
| Analizada | Baja (2) | 0.25% | — | Zhenfeng13 My-blog | 18/8/2025 | 17/6/2026 | A weakness has been identified in zhenfeng13 My-Blog up to 1.0.0. This issue affects some unknown processing of the file /admin/tags/save of the component Tag Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.55% | — | Zhenfeng13 My-blog | 18/8/2025 | 17/6/2026 | A security flaw has been discovered in zhenfeng13 My-Blog 1.0.0. This vulnerability affects unknown code of the file /blog/comment of the component Frontend Blog Article Comment Handler. The manipulation leads to authentication bypass by capture-replay. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Baja (1.9) | 0.27% | — | Zhenfeng13 My-blog | 8/8/2025 | 17/6/2026 | A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0. It has been classified as problematic. Affected is an unknown function of the file /admin/categories/save of the component Category Handler. The manipulation of the argument categoryName leads to cross site scripting. It is possible to launch the attack… | |
| Analizada | Baja (2.1) | 0.23% | — | Zhenfeng13 My-blog | 8/8/2025 | 17/6/2026 | A vulnerability was found in zhenfeng13 My-Blog up to 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /admin/tags/save. The manipulation of the argument tagName leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Baja (2.1) | 0.43% | — | Fengoffice Feng Office | 9/6/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /application/models/ApplicationDataObject.class.php of the component Document Upload Handler. The manipulation leads to xml external entity reference.… |