Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

474 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.28%—Realjerrytang TacomallAI29/9/20262/10/2026
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The…
AplazadaMedia (5.3)0.18%—Mall4jAI28/9/202630/9/2026
mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled user accounts can indefinitely renew their sessions through the POST /token/refresh endpoint, retaining access that account disabling…
AplazadaBaja (2.1)0.16%—Mall4jAI28/9/202630/9/2026
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the…
AplazadaAlta (7.1)0.24%—Mall4jAI28/9/20261/10/2026
mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.
AplazadaMedia (5.3)0.18%—Mall4jAI28/9/202630/9/2026
mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize…
AplazadaMedia (6.3)0.27%—Mall4jAI28/9/202630/9/2026
mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for…
AplazadaMedia (6.9)0.29%—Mall4jAI28/9/202630/9/2026
mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.
AplazadaCrítica (9.3)0.37%—Mall4jAI28/9/20261/10/2026
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and…
Pendiente de análisisAlta (7.5)0.49%—Smallrye Fault ToleranceAIQuarkusAI21/9/202625/9/2026
A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request.…
AplazadaBaja (2)0.41%—Newbee-ltd Newbee-mallAI20/9/202624/9/2026
A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argument goodsName results in cross site scripting. The attack may be initiated remotely.…
Pendiente de análisisMedia (5.3)0.58%—Smallrye JWTAI17/9/202621/9/2026
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch URL by directly concatenating the attacker-controlled kid header value from an…
AplazadaMedia (5.3)0.49%—Kagisearch SmallwebAI13/9/202615/9/2026
A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site scripting. The attack is possible to be…
AplazadaBaja (2.9)0.48%—Phpgurukul Small CRMAI13/9/202616/9/2026
A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack remotely. The complexity of an attack is…
AplazadaMedia (5.3)0.47%—Exrick XmallAI13/9/202614/9/2026
A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site scripting. Remote exploitation of the…
AplazadaMedia (4.8)0.37%—Linlinjava LitemallAI13/9/202616/9/2026
A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack…
AplazadaMedia (4.8)0.37%—Linlinjava LitemallAI13/9/202614/9/2026
A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site scripting. The attack may be initiated remotely.…
AplazadaMedia (6.1)0.25%—Guchengwuyue YshopmallAI9/9/202614/9/2026
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
Pendiente de análisisAlta (7.5)0.61%—Smallrye GraphqlAI31/8/20261/9/2026
A flaw was found in SmallRye GraphQL. The number scalar coercion for BigInteger does not properly validate the magnitude of float or string inputs. An unauthenticated remote attacker can exploit this by sending a GraphQL query containing a large exponent float literal. This can lead to the allocation of extremely…
AplazadaBaja (2.1)0.44%—Macrozheng MallAI29/8/20261/9/2026
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The…
AplazadaBaja (2.3)0.29%—Macrozheng MallAI29/8/202631/8/2026
A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The…
AplazadaMedia (5.3)0.39%—Macrozheng MallAI25/8/202627/8/2026
A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub…
AplazadaMedia (6.3)0.33%—Meshtastic MallaAI21/8/20269/9/2026
Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any participant on a public Meshtastic MQTT broker can…
AplazadaBaja (2.9)0.44%—Macrozheng MallAI9/8/202613/8/2026
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated…
AplazadaMedia (4.3)0.33%—Thememove EdumallAI13/7/202613/7/2026
Missing Authorization vulnerability in ThemeMove EduMall edumall allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EduMall: from n/a through <= 4.5.1.
AplazadaBaja (2.1)0.41%—Macrozheng MallAI9/7/20269/7/2026
A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly…