Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 212 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.3) | 0.65% | — | Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem | 30/12/2025 | 24/9/2026 | Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | |
| Analizada | Alta (8) | 0.49% | — | Aaluoxiang OA System | 16/9/2025 | 17/6/2026 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the alph parameters in src/main/Java/cn/gson/oasys/controller/address/AddrController | |
| Analizada | Media (5.6) | 0.47% | — | Aaluoxiang OA System | 10/9/2025 | 17/6/2026 | oasys v1.1 is vulnerable to Directory Traversal in ProcedureController. | |
| Analizada | Crítica (9.8) | 0.63% | — | Aaluoxiang OA System | 29/8/2025 | 17/6/2026 | SQL injection vulnerability in oa_system oasys v.1.1 allows a remote attacker to execute arbitrary code via the allDirector() method declaration in src/main/java/cn/gson/oasys/mappers/AddressMapper.java | |
| Analizada | Media (5.3) | 0.40% | — | Aaluoxiang OA System | 28/6/2025 | 17/6/2026 | A vulnerability was found in aaluoxiang oa_system up to c3a08168c144f27256a90838492c713f55f1b207 and classified as critical. This issue affects the function outAddress of the component External Address Book Handler. The manipulation leads to sql injection. The attack may be initiated remotely. This product does not… | |
| Analizada | Media (5.3) | 0.68% | — | Aaluoxiang OA System | 4/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the function image of the file src/main/java/cn/gson/oasys/controller/process/ProcedureController.java. The manipulation leads to path traversal. It is possible to initiate the… | |
| Analizada | Media (5.3) | 0.70% | — | Aaluoxiang OA System | 3/6/2025 | 17/6/2026 | A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this issue is the function image of the file src/main/java/cn/gson/oasys/controller/user/UserpanelController.java. The manipulation leads to path traversal. The attack may be… | |
| Analizada | Media (6.1) | 0.27% | — | Hailey888 OA System | 14/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the userName parameter at /login/LoginsController.java. | |
| Analizada | Media (6.1) | 0.27% | — | Hailey888 OA System | 14/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the outtype parameter at /address/AddrController.java. | |
| Analizada | Media (6.1) | 0.27% | — | Hailey888 OA System | 14/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the password parameter at /mail/MailController.java. | |
| Analizada | Media (6.1) | 0.27% | — | Hailey888 OA System | 14/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /daymanager/daymanageabilitycontroller.java. | |
| Analizada | Media (6.1) | 0.27% | — | Hailey888 OA System | 14/5/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in OA System before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter at /inform/InformManageController.java. | |
| Analizada | Media (5.1) | 0.30% | — | Hailey888 OA System | 8/4/2025 | 17/6/2026 | A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file cn/gson/oasys/controller/mail/MailController.java of the component Backend. The manipulation of the argument MailNumberId leads to cross site scripting. The attack… | |
| Analizada | Media (5.1) | 0.31% | — | Hailey888 OA System | 8/4/2025 | 17/6/2026 | A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the file cn/gson/oass/controller/address/AddrController. java of the component Backend. The manipulation of the argument outtype leads to cross site… | |
| Analizada | Media (5.1) | 0.30% | — | Hailey888 OA System | 8/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Backend. The manipulation of the argument scheduleList leads to cross site… | |
| Analizada | Media (5.1) | 0.30% | — | Hailey888 OA System | 8/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component Backend. The manipulation of the argument menu leads to cross site scripting.… | |
| Analizada | Media (5.3) | 0.40% | — | Hailey888 OA System | 7/4/2025 | 17/6/2026 | A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The manipulation of the argument Username leads to cross site scripting. The attack… | |
| Analizada | Media (5.3) | 0.55% | — | Aaluoxiang OA System | 4/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some unknown processing of the file src/main/resources/mappers/address-mapper.xml. The manipulation of the argument outtype leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Alta (7.5) | 1.5% | — | Xinfu OA System | 28/4/2021 | 17/6/2026 | SQL Injection in Xinhu OA System v1.8.3 allows remote attackers to obtain sensitive information by injecting arbitrary commands into the "typeid" variable of the "createfolderAjax" function in the "mode_worcAction.php" component. |