Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.3)0.65%—Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem30/12/202524/9/2026
Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms.
AnalizadaAlta (8)0.49%—Aaluoxiang OA System16/9/202517/6/2026
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController
AnalizadaMedia (5.6)0.47%—Aaluoxiang OA System10/9/202517/6/2026
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
AnalizadaCrítica (9.8)0.63%—Aaluoxiang OA System29/8/202517/6/2026
SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java
AnalizadaMedia (5.3)0.40%—Aaluoxiang OA System28/6/202517/6/2026
A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address Book Handler. The manipulation leads to sql injection. The attack may be initiated remotely. This product does not…
AnalizadaMedia (5.3)0.68%—Aaluoxiang OA System4/6/202517/6/2026
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController.java. The manipulation leads to path traversal. It is possible to initiate the…
AnalizadaMedia (5.3)0.70%—Aaluoxiang OA System3/6/202517/6/2026
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file src/main/java/cn/gson/oasys/controller/user/UserpanelController.java. The manipulation leads to path traversal. The attack may be…
AnalizadaMedia (6.1)0.27%—Hailey888 OA System14/5/202517/6/2026
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java.
AnalizadaMedia (6.1)0.27%—Hailey888 OA System14/5/202517/6/2026
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java.
AnalizadaMedia (6.1)0.27%—Hailey888 OA System14/5/202517/6/2026
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java.
AnalizadaMedia (6.1)0.27%—Hailey888 OA System14/5/202517/6/2026
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java.
AnalizadaMedia (6.1)0.27%—Hailey888 OA System14/5/202517/6/2026
A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java.
AnalizadaMedia (5.1)0.30%—Hailey888 OA System8/4/202517/6/2026
A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file cn/gson/oasys/controller/mail/MailController.java of the component Backend. The manipulation of the argument MailNumberId leads to cross site scripting. The attack…
AnalizadaMedia (5.1)0.31%—Hailey888 OA System8/4/202517/6/2026
A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the file cn/gson/oass/controller/address/AddrController. java of the component Backend. The manipulation of the argument outtype leads to cross site…
AnalizadaMedia (5.1)0.30%—Hailey888 OA System8/4/202517/6/2026
A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Backend. The manipulation of the argument scheduleList leads to cross site…
AnalizadaMedia (5.1)0.30%—Hailey888 OA System8/4/202517/6/2026
A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to cross site scripting.…
AnalizadaMedia (5.3)0.40%—Hailey888 OA System7/4/202517/6/2026
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack…
AnalizadaMedia (5.3)0.55%—Aaluoxiang OA System4/3/202517/6/2026
A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of the argument outtype leads to sql injection. The attack may be initiated remotely. The exploit has…
ModificadaAlta (7.5)1.5%—Xinfu OA System28/4/202117/6/2026
SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component.