Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.37%—Zsadmin2025 Zs-adminAIMybatis-plusAI21/7/202623/7/2026
A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the function getTenantId of the file /api/system/sys/dept/page of the component MyBatis-Plus Tenant Plugin. Such manipulation of the argument X-Tenant-Id leads to authorization bypass. The attack may be…
AplazadaMedia (5.5)0.43%—Liyupi Yu-pictureAIBaomidou Mybatis-plusAI26/4/202617/6/2026
A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file yu-picture-backend/src/main/java/com/yupi/yupicturebackend/service/impl/PictureServiceImpl.java of the component MyBatis-Plus. Executing a manipulation of the argument…
AplazadaBaja (2.1)0.40%—Joeybling Springboot MybatisplusAI12/7/202517/6/2026
A vulnerability has been found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26 and classified as critical. This vulnerability affects the function Download of the file /file/download. The manipulation of the argument Name leads to path traversal. The attack can be initiated remotely.…
AplazadaBaja (2.1)0.27%—Joeybling Springboot MybatisplusAI12/7/202517/6/2026
A vulnerability, which was classified as critical, was found in JoeyBling SpringBoot_MyBatisPlus up to a6a825513bd688f717dbae3a196bc9c9622fea26. This affects the function SysFileController of the file /file/upload. The manipulation of the argument portraitFile leads to unrestricted upload. It is possible to initiate…
AnalizadaMedia (6.5)0.36%—Huangjian888 Jeeweb-mybatis-springboot5/5/202517/6/2026
Incorrect access control in the component /admin/sys/datasource/ajaxList of jeeweb-mybatis-springboot v0.0.1.RELEASE allows attackers to access sensitive information via a crafted payload.
AplazadaMedia (5.4)0.37%—Mybatis PlusAI28/5/202417/6/2026
A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database information via a Boolean blind injection. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL…
ModificadaCrítica (9.8)1.2%—Mybatis5/4/202317/6/2026
A SQL injection vulnerability in Mybatis plus below 3.5.3.1 allows remote attackers to execute arbitrary SQL commands via the tenant ID valuer. NOTE: the vendor's position is that this can only occur in a misconfigured application; the documentation discusses how to develop applications that avoid SQL injection.
ModificadaCrítica (9.8)0.90%—Mybatis Mapper2/9/202217/6/2026
Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds function.
ModificadaCrítica (9.8)2.0%—Baomidou Mybatis-plus22/3/202217/6/2026
MyBatis plus v3.4.3 was discovered to contain a SQL injection vulnerability via the Column parameter in /core/conditions/AbstractWrapper.java. NOTE: the vendor's position is that the reported execution of a SQL statement was intended behavior.
ModificadaAlta (8.1)1.8%—Mybatis10/10/202017/6/2026
MyBatis before 3.5.6 mishandles deserialization of object streams.