Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | UZY Ssm-mallAI | 27/5/2026 | 17/6/2026 | SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the ProductMapper.xml and /OrderUtil.java components | |
| Analizada | Media (6.5) | 0.36% | — | Ghostxbh Uzy-ssm-mall | 8/10/2025 | 17/6/2026 | A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying a crafted input. | |
| Analizada | Media (6.5) | 0.35% | — | Ghostxbh Uzy-ssm-mall | 8/10/2025 | 17/6/2026 | An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying crafted XML data. | |
| Analizada | Media (5.3) | 0.34% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted… | |
| Analizada | Media (5.1) | 0.40% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the argument product_name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Analizada | Media (5.3) | 0.59% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the function ForeProductListController of the file /mall/product/0/20. The manipulation of the argument orderBy leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.57% | — | Ghostxbh Uzy-ssm-mall | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown part of the file /mall/user/uploadUserHeadImage. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the… |