Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.40% | — | Wangl1989 Mysiteforme | 4/3/2025 | 17/6/2026 | A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1. | |
| Analizada | Alta (8.6) | 0.44% | — | Wangl1989 Mysiteforme | 15/1/2025 | 17/6/2026 | MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download. | |
| Analizada | Crítica (9.1) | 0.51% | — | Wangl1989 Mysiteforme | 15/1/2025 | 17/6/2026 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField. | |
| Analizada | Alta (7.5) | 0.45% | — | Wangl1989 Mysiteforme | 15/1/2025 | 17/6/2026 | MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list. | |
| Analizada | Crítica (9.1) | 0.51% | — | Wangl1989 Mysiteforme | 15/1/2025 | 17/6/2026 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add. | |
| Analizada | Crítica (9.1) | 0.51% | — | Wangl1989 Mysiteforme | 15/1/2025 | 17/6/2026 | MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField. | |
| Analizada | Alta (7.5) | 0.51% | — | Wangl1989 Mysiteforme | 15/1/2025 | 17/6/2026 | MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file. | |
| Analizada | Media (5.3) | 0.56% | — | Wangl1989 Mysiteforme | 5/1/2025 | 17/6/2026 | A vulnerability was found in wangl1989 mysiteforme 1.0. It has been rated as critical. This issue affects the function doContent of the file src/main/java/com/mysiteform/admin/controller/system/FileController. The manipulation of the argument content leads to server-side request forgery. The attack may be initiated… | |
| Analizada | Media (5.1) | 0.44% | — | Wangl1989 Mysiteforme | 5/1/2025 | 17/6/2026 | A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The manipulation of the argument test leads to unrestricted upload. The attack can be initiated… | |
| Analizada | Media (5.1) | 0.34% | — | Wangl1989 Mysiteforme | 5/1/2025 | 17/6/2026 | A vulnerability was found in wangl1989 mysiteforme 1.0. It has been classified as problematic. This affects the function RestResponse of the file src/main/java/com/mysiteforme/admin/controller/system/SiteController. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The… | |
| Analizada | Media (5.3) | 0.60% | — | Wangl1989 Mysiteforme | 5/1/2025 | 17/6/2026 | A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 0.91% | — | Wangl1989 Mysiteforme | 24/5/2022 | 17/6/2026 | mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. | |
| Analizada | Media (5.4) | 0.44% | — | Wangl1989 Mysiteforme | 20/1/2022 | 17/6/2026 | mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management. | |
| Modificada | Media (6.5) | 0.42% | — | Wangl1989 Mysiteforme | 19/1/2022 | 17/6/2026 | mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added |