Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2818▲ 71 respecto a la semana anterior
Críticas / altas1488▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
2106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.29% | — | Social Media Share Buttons Social Sharing IconsAI | 1/10/2026 | 1/10/2026 | The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Trex Digital Smart Manufacturing Systems Trex MESAI | 30/9/2026 | 30/9/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL Injection. This issue affects Trex MES: through 2026-09-29. | |
| Aplazada | Alta (7.1) | 0.29% | — | Flowring AgentflowAI | 29/9/2026 | 30/9/2026 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter. | |
| Aplazada | Crítica (9.3) | 0.27% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file. | |
| Aplazada | Alta (8.7) | 0.23% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter. | |
| Aplazada | Crítica (9.3) | 0.28% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Aplazada | Crítica (9.3) | 0.34% | — | Flowring AgentflowAI | 29/9/2026 | 29/9/2026 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | |
| Aplazada | Alta (7.6) | 0.28% | — | StringerAI | 28/9/2026 | 30/9/2026 | Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the Stringer server to send arbitrary HTTP/HTTPS requests to internal networks, localhost services, and cloud metadata endpoints (e.g. AWS… | |
| Pendiente de análisis | Crítica (9.3) | 0.30% | — | Yzcheng90 X-springbootAI | 25/9/2026 | 30/9/2026 | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emailOrMobileLogin endpoint with a known email or mobile number. | |
| Pendiente de análisis | Crítica (9.3) | 0.29% | — | Yzcheng90 X-springbootAI | 25/9/2026 | 28/9/2026 | X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobile numbers or email addresses, read them from responses, and authenticate as… | |
| Pendiente de análisis | Alta (8.6) | 0.31% | — | Yzcheng90 X-springbootAI | 25/9/2026 | 29/9/2026 | X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords for any account including the super administrator, rebind roles, or delete users… | |
| Pendiente de análisis | Media (6.9) | 0.32% | — | Yzcheng90 X-springbootAI | 25/9/2026 | 29/9/2026 | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send arbitrary SMS messages through any tenant's SMS provider, enabling SMS bombing and… | |
| Aplazada | Alta (7.2) | 0.24% | — | Restaurant Menu AND Food OrderingAI | 25/9/2026 | 25/9/2026 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'phone_number' parameter in all versions up to, and including, 2.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Baja (2.1) | 0.23% | — | Bladex SpringbladeAI | 24/9/2026 | 25/9/2026 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of the component user-auth-info Endpoint. This manipulation of the argument userId… | |
| Aplazada | Media (6.1) | 0.22% | — | MailspringAI | 24/9/2026 | 30/9/2026 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a… | |
| Aplazada | Media (5.5) | 0.29% | — | Talelin Lin-cms-spring-bootAI | 24/9/2026 | 29/9/2026 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Media (5.5) | 0.29% | — | Talelin LIN CMS Spring BootAI | 24/9/2026 | 24/9/2026 | A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Executing a manipulation can lead to improper authorization. The attack may be performed… | |
| Aplazada | Media (5.5) | 0.29% | — | Talelin Lin-cms-spring-bootAI | 24/9/2026 | 24/9/2026 | A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is… | |
| Aplazada | Baja (2.1) | 0.34% | — | Weiqingwen Spring-boot-forumAI | 23/9/2026 | 29/9/2026 | A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the component Avatar Upload. The manipulation of the argument Username leads to path… | |
| Aplazada | Baja (1.3) | 0.15% | — | Sfturing Hosp OrderAI | 23/9/2026 | 24/9/2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Password Handler. The manipulation leads to one-way hash without salt. The attack may… | |
| Aplazada | Baja (2.1) | 0.16% | — | Sfturing Hosp OrderAI | 23/9/2026 | 24/9/2026 | A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java. Executing a manipulation can lead to cross-site request forgery. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.9) | 0.21% | — | Sfturing Hosp OrderAI | 23/9/2026 | 29/9/2026 | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation results in cleartext transmission of sensitive information. The attack can be… | |
| Aplazada | Baja (1.9) | 0.08% | — | Sfturing Hosp OrderAI | 23/9/2026 | 23/9/2026 | A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such manipulation leads to cleartext storage of sensitive information. The attack can only… | |
| Aplazada | Baja (2.9) | 0.26% | — | Sfturing Hosp OrderAI | 23/9/2026 | 23/9/2026 | A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It… | |
| Pendiente de análisis | Alta (7.5) | 0.46% | — | Request-filtering-agentAI | 22/9/2026 | 25/9/2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rejecting a literal private-IP host such as 169.254.169.254 or 127.0.0.1. Because… |