Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 25/9/2026 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component OAuth2 Client. The… | |
| Aplazada | Media (5.5) | 0.28% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 5/10/2026 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The… | |
| Aplazada | Baja (2.1) | 0.40% | — | Ruoyi-vue-proAI | 24/9/2026 | 24/9/2026 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing a manipulation can lead to path… | |
| Aplazada | Baja (2.1) | 0.26% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 29/9/2026 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing a manipulation results in cross site scripting.… | |
| Aplazada | Baja (2.1) | 0.23% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 24/9/2026 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component GoView Data Endpoint. Such… | |
| Aplazada | Baja (2.1) | 0.20% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 25/9/2026 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI Knowledge Module. This manipulation of the argument url causes server-side request forgery. The… | |
| Aplazada | Alta (8.8) | 0.69% | — | Ruoyi-vue-plusAI | 15/9/2026 | 22/9/2026 | An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components | |
| Aplazada | Media (5.3) | 0.35% | — | Dromara Ruoyi-vue-plusAI | 21/8/2026 | 24/8/2026 | A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/FlwCategoryController/FlwSpelController/TestLeaveController of the component Workflow Endpoint. Such manipulation leads to improper authorization. The attack can be… | |
| Aplazada | Baja (2.1) | 0.47% | — | Ruoyi-vueAI | 19/8/2026 | 21/8/2026 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. This impacts the function fileDownload/resourceDownload of the file ruoyi-admin/src/main/java/com/ruoyi/web/controller/common/CommonController.java of the component Common Download Endpoint. Performing a manipulation of the argument fileName/resource… | |
| Aplazada | Alta (7.1) | 0.46% | — | Ruoyi-vue-plusAI | 30/6/2026 | 14/7/2026 | RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization annotation, so the endpoints are gated only by global authentication. Any… | |
| Aplazada | Alta (7.1) | 0.40% | — | Ruoyi-vue-proAI | 29/6/2026 | 14/7/2026 | ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests… | |
| Aplazada | Media (5.5) | 0.65% | — | Iocoder Ruoyi-vue-proAI | 29/6/2026 | 29/6/2026 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java of the component AppFileController File Upload Endpoint.… | |
| Aplazada | Media (5.3) | 0.34% | — | Ruoyi-vueAI | 24/5/2026 | 23/7/2026 | A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. Performing a manipulation results in unrestricted upload. The attack is possible to be carried out remotely. The vendor was contacted… | |
| Aplazada | Baja (2.1) | 0.35% | — | Dromara Ruoyi-vue-plusAI | 20/2/2026 | 17/6/2026 | A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be initiated remotely. The exploit is… | |
| Aplazada | Alta (7) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 22/1/2026 | 17/6/2026 | Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them… | |
| Analizada | Crítica (9.4) | 0.73% | — | Dromara Ruoyi-vue-plus | 8/1/2026 | 17/6/2026 | The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing. | |
| Aplazada | Alta (8.8) | 0.34% | — | Carrier I-vu Gen5 RouterAIAutomatedlogic I-vu Gen5 RouterAI | 27/11/2025 | 17/6/2026 | — | |
| Aplazada | Media (6.9) | 0.31% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser . | |
| Aplazada | Crítica (9.2) | 0.33% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server. | |
| Aplazada | Media (5.4) | 0.12% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter not being sanitized. | |
| Aplazada | Alta (8.6) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions. | |
| Analizada | Baja (2.1) | 0.32% | — | Iocoder Ruoyi-vue-pro | 26/9/2025 | 17/6/2026 | A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early… | |
| Analizada | Baja (2.1) | 0.33% | — | Iocoder Ruoyi-vue-pro | 12/9/2025 | 17/6/2026 | A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The… | |
| Analizada | Baja (2.1) | 0.33% | — | Iocoder Ruoyi-vue-pro | 12/9/2025 | 17/6/2026 | A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 1.1% | — | Dromara Ruoyi-vue-plus | 30/6/2025 | 17/6/2026 | A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler. The manipulation of the argument filePath leads to path… |