Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2637▼ 209 respecto a la semana anterior
Críticas / altas1378▲ 149 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.29% | — | Talelin Lin-cms-spring-bootAI | 24/9/2026 | 29/9/2026 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation leads to improper authorization. It is possible to… | |
| Aplazada | Media (5.5) | 0.29% | — | Talelin LIN CMS Spring BootAI | 24/9/2026 | 24/9/2026 | A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Executing a manipulation can lead to improper authorization. The attack may be performed… | |
| Aplazada | Media (5.5) | 0.29% | — | Talelin Lin-cms-spring-bootAI | 24/9/2026 | 24/9/2026 | A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is… | |
| Aplazada | Media (6.9) | 0.71% | — | Mybooks TalebookAI | 19/8/2026 | 9/9/2026 | MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though the frontend hides registration controls when the flag is false. An… | |
| Aplazada | Alta (8.7) | 0.45% | — | MybooksAITalebookAI | 19/8/2026 | 9/9/2026 | MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings in webserver/handlers/admin.py applies the auth decorator but does not check the self.admin_user property, unlike the corresponding GET handler. Any authenticated regular… | |
| Aplazada | Crítica (9.4) | 0.50% | — | MybooksAITalebookAI | 19/8/2026 | 9/9/2026 | MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quotes or newline characters, and SettingsLoader.dumpfile in webserver/loader.py… | |
| Aplazada | Baja (2.9) | 0.57% | — | Mangroup DtaleAI | 15/8/2026 | 20/8/2026 | A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/auth.py of the component Login Endpoint. Such manipulation leads to improper restriction of excessive authentication attempts. The attack can be executed remotely. This attack is characterized by high… | |
| Aplazada | Baja (2.9) | 0.49% | — | Mangroup DtaleAI | 15/8/2026 | 20/8/2026 | A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the file dtale/app.py of the component Flask Session Cookie. This manipulation causes insufficiently random values. Remote exploitation of the attack is possible. The attack's complexity is rated as high.… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft Enterprise HCM Talent Acquisition Manager | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent… | |
| Aplazada | Alta (7.1) | 0.25% | — | Artale Wedding PhotographyAI | 2/7/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. | |
| Aplazada | Baja (2.1) | 0.21% | — | Talelin Lin-cms-spring-bootAI | 30/5/2026 | 22/7/2026 | A vulnerability was detected in TaleLin lin-cms-spring-boot up to 0.2.1. This issue affects some unknown processing of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. The manipulation results in improper access controls. The attack may be launched… | |
| Aplazada | Alta (8.2) | 0.28% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available. | |
| Aplazada | Media (5.4) | 0.23% | — | Talend Administration CenterAI | 20/5/2026 | 23/7/2026 | A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that can be triggered by a different user. | |
| Pendiente de análisis | Crítica (9.8) | 0.92% | — | Talend JobserverAITalend RuntimeAI | 14/4/2026 | 17/6/2026 | A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend JobServer by requiring TLS client authentication for the… | |
| Analizada | Media (5.3) | 0.86% | — | MAN D-tale | 6/4/2026 | 17/6/2026 | D-Tale is the combination of a Flask back-end and a React front-end to view & analyze Pandas data structures. Prior to 3.22.0, users hosting D-Tale publicly while using a redis or shelf storage layer could be vulnerable to remote code execution allowing attackers to run malicious code on the server. This vulnerability… | |
| Aplazada | Alta (8.7) | 0.47% | — | Hytale Modding WikiAI | 2/4/2026 | 24/7/2026 | The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. In version 1.2.0 and prior, the quickUpload() endpoint validates uploaded files by checking their MIME type (via PHP's finfo, which inspects file contents) but constructs the stored filename using the client-supplied file… | |
| Analizada | Media (4.3) | 0.29% | — | Hytalemodding Wiki | 18/3/2026 | 17/6/2026 | The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object Reference (IDOR) vulnerability in versions of the wiki prior to 1.0.0 exposes mod authors' personal information - including full names and email addresses - to any authenticated user who visits a… | |
| Analizada | Alta (8.1) | 0.96% | — | MAN D-tale | 21/2/2026 | 17/6/2026 | D-Tale is a visualizer for pandas data structures. Versions prior to 3.20.0 are vulnerable to Remote Code Execution through the /save-column-filter endpoint. Users hosting D-Tale publicly can be vulnerable to remote code execution allowing attackers to run malicious code on the server. This issue has been fixed in… | |
| Aplazada | Crítica (9.8) | 0.31% | — | Kolay Software INC TalenticsAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection. This issue affects Talentics: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (7.5) | 0.36% | — | Talemy Spirit FrameworkAI | 2/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.This issue affects Spirit Framework: from n/a through 1.2.13. | |
| Analizada | Media (6.1) | 0.26% | — | Tale Project Tale | 29/1/2026 | 17/6/2026 | Cross Site Scripting vulnerability in tale v.2.0.5 allows an attacker to execute arbitrary code. | |
| Aplazada | Baja (2.9) | 0.32% | — | Talelin Lin-cmsAI | 28/12/2025 | 17/6/2026 | A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/password causes password in configuration file. The attack is possible to be carried out remotely. The complexity of an… | |
| Aplazada | Media (5.4) | 0.19% | — | Talent Software E-bap AutomationAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Reflected XSS. This issue affects e-BAP Automation: before 42957. | |
| Aplazada | Media (5.4) | 0.19% | — | Talentyazilim UnisAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software UNIS allows Reflected XSS. This issue affects UNIS: before 42957. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Talentyazilim UnisAI | 9/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection. This issue affects UNIS: before 42321. |