Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.23%—Newbee-ltd Newbee-mallAI6/10/20266/10/2026
A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be…
AplazadaBaja (2)0.41%—Newbee-ltd Newbee-mallAI20/9/202624/9/2026
A security flaw has been discovered in newbee-ltd newbee-mall up to 1.0.0. Impacted is an unknown function of the file controller/common/UploadController.java of the component Goods Save Endpoint. Performing a manipulation of the argument goodsName results in cross site scripting. The attack may be initiated remotely.…
AplazadaBaja (2.1)0.34%—Newbee-ltd Newbee-mallAI18/2/202617/6/2026
A vulnerability was found in newbee-ltd newbee-mall up to a069069b07027613bf0e7f571736be86f431faee. Affected is an unknown function of the component Multiple Endpoints. Performing a manipulation results in cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been made public and…
AnalizadaCrítica (9.3)0.29%—Newbee-mall Project Newbee-mall12/2/202614/7/2026
newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover…
AnalizadaCrítica (9.3)0.57%—Newbee-mall Project Newbee-mall12/2/202614/7/2026
newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow…
AnalizadaBaja (2)0.41%—Newbee-ltd Newbee-mall-plus30/12/202517/6/2026
A vulnerability was determined in newbee-mall-plus 2.0.0. This impacts the function Upload of the file src/main/java/ltd/newbee/mall/controller/common/UploadController.java of the component Product Information Edit Page. This manipulation of the argument File causes unrestricted upload. The attack may be initiated…
AplazadaBaja (2.9)0.46%—Newbee-ltd Newbee-mall-plusAI7/11/202517/6/2026
A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill of the file /seckillExecution/. The manipulation of the argument userid leads to authorization bypass. It is possible to initiate the attack remotely. The attack is considered to have high complexity.…
AnalizadaBaja (2.9)0.45%—Newbee-mall Project Newbee-mall15/9/202517/6/2026
A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The manipulation results in guessable captcha. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The exploit has…
AnalizadaBaja (2.1)0.30%—Newbee-mall Project Newbee-mall15/9/202517/6/2026
A vulnerability has been found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. This issue affects the function paySuccess of the file /paySuccess of the component Order Status Handler. The manipulation of the argument orderNo leads to improper authorization. Remote exploitation of the attack is…
AnalizadaMedia (5.3)0.53%—Newbee-mall Project Newbee-mall5/5/202517/6/2026
A vulnerability has been found in newbee-mall 1.0 and classified as critical. Affected by this vulnerability is the function Upload of the file ltd/newbee/mall/controller/common/UploadController.java. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit…
AnalizadaMedia (5.1)0.34%—Newbee-mall Project Newbee-mall7/2/202517/6/2026
A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the function save of the file /admin/categories/save of the component Add Category Page. The manipulation of the argument categoryName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has…
AnalizadaAlta (8.1)0.34%—Newbee-mall Project Newbee-mall28/10/202417/6/2026
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
ModificadaMedia (5.4)0.33%—Newbee-mall Project Newbee-mall4/5/202317/6/2026
Insecure permissions in the updateUserInfo function of newbee-mall before commit 1f2c2dfy allows attackers to obtain user account information.
ModificadaCrítica (9.8)1.1%—Newbee-mall Project Newbee-mall10/4/202217/6/2026
Newbee-Mall v1.0.0 was discovered to contain an arbitrary file upload via the Upload function at /admin/goods/edit.
ModificadaMedia (6.1)0.56%—Newbee-mall Project Newbee-mall10/4/202217/6/2026
A cross-site scripting (XSS) vulnerability at /admin/goods/update in Newbee-Mall v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the goodsName parameter.
ModificadaAlta (7.5)0.87%—Newbee-mall Project Newbee-mall26/1/202117/6/2026
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through NewBeeMallIndexConfigServiceImpl.java. Unauthorized changes can be made to any user information through the userID.
ModificadaCrítica (9.8)1.6%—Newbee-mall Project Newbee-mall26/1/202117/6/2026
newbee-mall all versions are affected by incorrect access control to remotely gain privileges through AdminLoginInterceptor.java. The authentication logic of the system's background /admin is in code AdminLoginInterceptor, which can be bypassed.
ModificadaMedia (6.1)0.66%—Newbee-mall Project Newbee-mall26/1/202117/6/2026
newbee-mall 1.0 is affected by cross-site scripting in shop-cart/settle. Users only need to write xss payload in their address information when buying goods, which is triggered when viewing the "View Recipient Information" of this order in "Order Management Office".
ModificadaCrítica (9.8)1.8%—Newbee-mall Project Newbee-mall18/11/201917/6/2026
main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCategoryId=&keyword= SQL Injection.