Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.29%—Talelin Lin-cms-spring-bootAI24/9/202629/9/2026
A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to…
AplazadaMedia (5.5)0.29%—Talelin Lin-cms-spring-bootAI24/9/202624/9/2026
A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is…
AplazadaBaja (2.1)0.21%—Talelin Lin-cms-spring-bootAI30/5/202622/7/2026
A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack may be launched…
AplazadaBaja (2.9)0.32%—Talelin Lin-cmsAI28/12/202517/6/2026
A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried out remotely. The complexity of an…
AplazadaBaja (2.1)0.32%—Chenjinchuang Lin-cms-tp5AI28/12/202517/6/2026
A flaw has been found in ChenJinchuang Lin-CMS-TP5 up to 0.3.3. This vulnerability affects the function Upload of the file application/lib/file/LocalUploader.php of the component File Upload Handler. Executing manipulation of the argument File can lead to code injection. The attack can be executed remotely. The…
ModificadaAlta (7.5)0.45%—Talelin Lin-cms-spring-boot19/7/202417/6/2026
Insecure Permissions vulnerability in lin-CMS Springboot v.0.2.1 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
AplazadaAlta (7.5)0.45%—Lin-cmsAI19/7/202417/6/2026
Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
ModificadaMedia (6.6)1.1%—Lin-cms Project Lin-cms9/11/202217/6/2026
An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator.
ModificadaAlta (7.5)5.0%—Talelin Lin-cms-spring-boot21/7/202217/6/2026
An access control issue in Lin CMS Spring Boot v0.2.1 allows attackers to access the backend information and functions within the application.
ModificadaCrítica (9.8)2.3%—Talelin Lin-cms-flask16/8/202117/6/2026
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
ModificadaMedia (6.1)1.3%—Talelin Lin-cms-flask16/8/202117/6/2026
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
ModificadaCrítica (9.8)2.0%—Talelin Lin-cms-flask16/8/202117/6/2026
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.