Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.48% | — | Seeyon A6AI | 29/9/2026 | 30/9/2026 | Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL… | |
| Aplazada | Crítica (9.3) | 0.65% | — | Seeyon OA A8AI | 21/4/2026 | 17/6/2026 | Seeyon OA A8 contains an unauthenticated arbitrary file write vulnerability in the /seeyon/htmlofficeservlet endpoint that allows remote attackers to write arbitrary files to the web application root by sending specially crafted POST requests with custom base64-encoded payloads. Attackers can write JSP webshells to… | |
| Analizada | Media (6.1) | 0.22% | — | Seeyon A8+ Collaborative Management | 16/1/2026 | 17/6/2026 | Cross site scripting vulnerability in seeyon Zhiyuan A8+ Collaborative Management Software 7.0 via the topValue parameter to the seeyon/main.do endpoint. | |
| Aplazada | Crítica (9.3) | 0.49% | — | Seeyon Zhiyuan OAAI | 30/10/2025 | 17/6/2026 | Seeyon Zhiyuan OA Web Application System versions up to and including 7.0 SP1 improperly decode and parse the `enc` parameter in thirdpartyController.do. The decoded map values can influence session attributes without sufficient authentication/authorization checks, enabling attackers to assign a session to arbitrary… | |
| Aplazada | Media (5.3) | 0.36% | — | Seeyon Zhiyuan OAAI | 25/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Seeyon Zhiyuan OA Web Application System up to 8.1 SP2. This affects the function this.oursNetService.getData of the file com\ours\www\ehr\openPlatform1\open4ClientType\controller\ThirdMenuController.class. The manipulation of the argument url leads to… | |
| Analizada | Media (5.3) | 0.50% | — | Seeyon OA WEB Application System | 11/5/2025 | 17/6/2026 | A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been rated as critical. Affected by this issue is the function postData of the file ROOT\WEB-INF\classes\com\ours\www\ehr\salary\service\data\EhrSalaryPayrollServiceImpl.class of the component Beetl Template Handler. The manipulation… | |
| Analizada | Media (5.3) | 0.55% | — | Seeyon OA WEB Application System | 11/5/2025 | 17/6/2026 | A vulnerability was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. It has been classified as problematic. Affected is the function Download of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\WEB-INF\lib\seeyon-apps-m3.jar!\com\seeyon\apps\m3\core\controller\M3CoreController.class of the… | |
| Analizada | Media (5.1) | 0.31% | — | Seeyon OA WEB Application System | 28/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\ssoproxy\jsp\ssoproxy.jsp. The manipulation of the argument Name leads to cross site scripting. It is… | |
| Analizada | Media (5.1) | 0.31% | — | Seeyon OA WEB Application System | 28/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\common\js\addDate\date.jsp of the component URL Parameter Handler. The manipulation leads… | |
| Analizada | Media (5.3) | 0.47% | — | Seeyon FE Collaborative Office Platform | 8/4/2025 | 17/6/2026 | A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform 5.5.2 and classified as critical. This issue affects some unknown processing of the file /sysform/042/check.js%70. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (6.9) | 0.39% | — | Seeyon Zhiyuan Interconnect FEAI | 6/3/2025 | 17/6/2026 | A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform up to 20250224. It has been rated as critical. Affected by this issue is some unknown functionality of the file /security/addUser.jsp. The manipulation of the argument groupId leads to sql injection. The attack may be launched… | |
| Aplazada | Crítica (9.8) | 33% | — | SeeyonoaAI | 2/4/2024 | 17/6/2026 | An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component. | |
| Modificada | Media (5.4) | 0.57% | — | Seeyon G6 Government Collaborative System | 30/3/2021 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in Zhiyuan G6 Government Collaboration System V6.1SP1, via the 'method' parameter to 'seeyon/hrSalary.do'. |