Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.29% | — | Talelin Lin-cms-spring-bootAI | 24/9/2026 | 29/9/2026 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Media (5.5) | 0.29% | — | Talelin Lin-cms-spring-bootAI | 24/9/2026 | 24/9/2026 | A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is… | |
| Aplazada | Baja (2.1) | 0.21% | — | Talelin Lin-cms-spring-bootAI | 30/5/2026 | 22/7/2026 | A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack may be launched… | |
| Aplazada | Baja (2.9) | 0.32% | — | Talelin Lin-cmsAI | 28/12/2025 | 17/6/2026 | A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried out remotely. The complexity of an… | |
| Aplazada | Baja (2.1) | 0.32% | — | Chenjinchuang Lin-cms-tp5AI | 28/12/2025 | 17/6/2026 | A flaw has been found in ChenJinchuang Lin-CMS-TP5 up to 0.3.3. This vulnerability affects the function Upload of the file application/lib/file/LocalUploader.php of the component File Upload Handler. Executing manipulation of the argument File can lead to code injection. The attack can be executed remotely. The… | |
| Modificada | Alta (7.5) | 0.45% | — | Talelin Lin-cms-spring-boot | 19/7/2024 | 17/6/2026 | Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component. | |
| Aplazada | Alta (7.5) | 0.45% | — | Lin-cmsAI | 19/7/2024 | 17/6/2026 | Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component. | |
| Modificada | Media (6.6) | 1.1% | — | Lin-cms Project Lin-cms | 9/11/2022 | 17/6/2026 | An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator. | |
| Modificada | Alta (7.5) | 5.0% | — | Talelin Lin-cms-spring-boot | 21/7/2022 | 17/6/2026 | An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application. | |
| Modificada | Crítica (9.8) | 2.3% | — | Talelin Lin-cms-flask | 16/8/2021 | 17/6/2026 | Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets. | |
| Modificada | Media (6.1) | 1.3% | — | Talelin Lin-cms-flask | 16/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'. | |
| Modificada | Crítica (9.8) | 2.0% | — | Talelin Lin-cms-flask | 16/8/2021 | 17/6/2026 | Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'. |