Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Zsadmin2025 Zs-adminAIMybatis-plusAI | 21/7/2026 | 23/7/2026 | A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Liyupi Yu-pictureAIBaomidou Mybatis-plusAI | 26/4/2026 | 17/6/2026 | A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulation of the argument… | |
| Aplazada | Baja (2.1) | 0.40% | — | Joeybling Springboot MybatisplusAI | 12/7/2025 | 17/6/2026 | A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. The manipulation of the argument Name leads to path traversal. The attack can be initiated remotely.… | |
| Aplazada | Baja (2.1) | 0.27% | — | Joeybling Springboot MybatisplusAI | 12/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The manipulation of the argument portraitFile leads to unrestricted upload. It is possible to initiate… | |
| Analizada | Media (6.5) | 0.36% | — | Huangjian888 Jeeweb-mybatis-springboot | 5/5/2025 | 17/6/2026 | Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload. | |
| Aplazada | Media (5.4) | 0.37% | — | Mybatis PlusAI | 28/5/2024 | 17/6/2026 | A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL… | |
| Modificada | Crítica (9.8) | 1.2% | — | Mybatis | 5/4/2023 | 17/6/2026 | A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection. | |
| Modificada | Crítica (9.8) | 0.90% | — | Mybatis Mapper | 2/9/2022 | 17/6/2026 | Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function. | |
| Modificada | Crítica (9.8) | 2.0% | — | Baomidou Mybatis-plus | 22/3/2022 | 17/6/2026 | MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior. | |
| Modificada | Alta (8.1) | 1.8% | — | Mybatis | 10/10/2020 | 17/6/2026 | MyBatis before 3.5.6 mishandles deserialization of object streams. |