Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.55% | — | JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access… | |
| Aplazada | Alta (8.7) | 0.46% | — | JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks. | |
| Aplazada | Alta (8.7) | 0.46% | — | JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileges, change data visibility to all data, and access all business… | |
| Aplazada | Alta (7.1) | 0.44% | — | JsherpAI | 21/9/2026 | 24/9/2026 | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through… | |
| Aplazada | Media (5.3) | 0.37% | — | Jsherpproject JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive tenant data including login names, validity dates, user quotas, and enabled state… | |
| Aplazada | Media (5.3) | 0.38% | — | JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameters to overwrite button-permission configurations for any role in the tenant without… | |
| Aplazada | Alta (7.1) | 0.55% | — | JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to obtain password hashes usable for offline cracking or direct authentication… | |
| Aplazada | Alta (8.7) | 0.55% | — | JsherpAI | 21/9/2026 | 22/9/2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that account's password to a known default value, enabling unauthorized… | |
| Aplazada | Alta (8.7) | 0.52% | — | JsherpAI | 21/9/2026 | 24/9/2026 | jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from low-privilege tenant user to tenant… | |
| Aplazada | Baja (2) | 0.23% | — | Jishenghua JsherpAI | 8/6/2026 | 23/7/2026 | A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-boot/src/main/java/com/jsh/erp/service/PlatformConfigService.java of the component platformConfig Add Endpoint. Executing a manipulation of the argument platformValue can lead to server-side request… | |
| Aplazada | Baja (2.1) | 0.32% | — | Jishenghua JsherpAI | 8/6/2026 | 23/7/2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component addAccountHeadAndDetail Endpoint. Such manipulation of the argument fileName… | |
| Aplazada | Baja (2) | 0.38% | — | Jishenghua JsherpAI | 11/5/2026 | 17/6/2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of the component updatePlatformConfigByKey Endpoint. Such manipulation of the argument weixinUrl leads to server-side… | |
| Analizada | Baja (2) | 0.67% | — | Jishenghua Jsherp | 29/1/2026 | 17/6/2026 | A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch… | |
| Analizada | Baja (2.1) | 0.52% | — | Jishenghua Jsherp | 28/1/2026 | 17/6/2026 | A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument configFile leads to path traversal. The attack may be launched remotely.… | |
| Analizada | Baja (2.1) | 0.38% | — | Jishenghua Jsherp | 28/1/2026 | 17/6/2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component com.jsh.erp.datasource.mappers.DepotItemMapperEx. The manipulation of the argument barCodes leads to sql injection. It… | |
| Analizada | Media (4.6) | 0.17% | — | Jishenghua Jsherp | 12/12/2025 | 17/6/2026 | jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint. | |
| Analizada | Media (4.6) | 0.17% | — | Jishenghua Jsherp | 12/12/2025 | 17/6/2026 | jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users. | |
| Analizada | Crítica (9.8) | 0.48% | — | Jishenghua Jsherp | 25/11/2025 | 17/6/2026 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks. | |
| Analizada | Crítica (9.8) | 0.48% | — | Jishenghua Jsherp | 25/11/2025 | 17/6/2026 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks. | |
| Analizada | Crítica (9.8) | 0.48% | — | Jishenghua Jsherp | 25/11/2025 | 17/6/2026 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks. | |
| Analizada | Crítica (9.8) | 0.48% | — | Jishenghua Jsherp | 25/11/2025 | 17/6/2026 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks. | |
| Analizada | Crítica (9.8) | 0.48% | — | Jishenghua Jsherp | 25/11/2025 | 17/6/2026 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads. | |
| Analizada | Alta (7.5) | 0.32% | — | Jishenghua Jsherp | 28/10/2025 | 17/6/2026 | Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request. | |
| Analizada | Alta (8.2) | 0.46% | — | Jishenghua Jsherp | 24/10/2025 | 17/6/2026 | jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. | |
| Modificada | Media (5.3) | 0.32% | — | Jishenghua Jsherp | 21/8/2025 | 5/7/2026 | Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method. |