Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.28%—Realjerrytang TacomallAI29/9/20262/10/2026
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The…
AplazadaMedia (5.3)0.34%—Tangyh Lamp-cloudAI21/9/202623/9/2026
lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to enumerate other employees' role codes, permission codes, and complete front-end…
AplazadaAlta (7.1)0.47%—Tangyh Lamp-cloudAI21/9/202622/9/2026
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications…
AplazadaAlta (7.1)0.49%—Tangyh Lamp-cloudAI21/9/202622/9/2026
lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education,…
AplazadaAlta (7.1)0.44%—Tangyh Lamp-cloudAI21/9/202622/9/2026
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attachment identifiers to the /anyone/file/down and /anyone/file/download endpoints, as…
AplazadaAlta (8.7)0.50%—Tangyh Lamp-cloudAI15/9/202622/9/2026
lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information including JVM classpath, filesystem paths,…
AplazadaMedia (6.5)0.29%—Tangible Loops AND LogicAI28/8/20268/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & Logic.
AplazadaCrítica (9.8)0.78%—Miantang Iot-phpAI5/8/202626/8/2026
Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='' and password='' limit 1"). An unauthenticated attacker can submit a payload such as pwd='…
AplazadaMedia (6.5)0.24%—Tangible Loops AND LogicAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Stored XSS.This issue affects Loops & Logic: from n/a through <= 4.2.3.
AplazadaAlta (8.1)0.44%—AshtangaAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
AplazadaMedia (6.4)0.26%—MicrotangoAI11/2/202617/6/2026
The Microtango plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'restkey' parameter of the mt_reservation shortcode in all versions up to, and including, 0.9.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.1)0.59%—Tangiblewp Listivo CoreAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP Listivo Core listivo-core allows PHP Local File Inclusion.This issue affects Listivo Core: from n/a through <= 2.3.77.
AplazadaAlta (7.5)0.54%—Tangiblewp Myhome CoreAI22/1/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TangibleWP MyHome Core myhome-core allows PHP Local File Inclusion.This issue affects MyHome Core: from n/a through <= 4.1.0.
AplazadaMedia (5.3)0.71%—Razvan Stanga Varnish Nginx Proxy CachingAI31/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Retrieve Embedded Sensitive Data.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3.
AplazadaBaja (2.8)0.12%—MustangAI28/11/202530/9/2026
Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
AnalizadaMedia (6.5)0.29%—Kutangguo Ktg-mes10/11/202517/6/2026
ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data.
AplazadaMedia (6.1)0.14%—Centangle TeamAI4/11/202517/6/2026
The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to modify plugin's settings via a forged request granted they can…
AplazadaMedia (4.3)0.14%—Tangiblewp Vehica CoreAI26/9/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in TangibleWP Vehica Core vehica-core allows Cross Site Request Forgery.This issue affects Vehica Core: from n/a through <= 1.0.100.
AplazadaMedia (5.9)0.22%—Razvan Stanga Varnish Nginx Proxy CachingAI28/8/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Razvan Stanga Varnish/Nginx Proxy Caching vcaching allows Stored XSS.This issue affects Varnish/Nginx Proxy Caching: from n/a through <= 1.8.3.
AplazadaMedia (5.3)0.32%—Centangle WOO Direct Checkout LiteAI6/6/202517/6/2026
Missing Authorization vulnerability in centangle Direct Checkout for WooCommerce Lite woo-direct-checkout-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Direct Checkout for WooCommerce Lite: from n/a through <= 1.0.3.
AnalizadaMedia (4.3)0.32%—Tanghc Code-gen15/4/202517/6/2026
code-gen <=2.0.6 is vulnerable to Incorrect Access Control. The project does not have permission control allowing anyone to access such projects.
AnalizadaMedia (4.8)0.50%—Aitangbao Springboot-manager11/3/202517/6/2026
A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sysDictDetail/add. The manipulation of the argument name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to…
AnalizadaMedia (4.8)0.50%—Aitangbao Springboot-manager11/3/202517/6/2026
A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /sysJob/add. The manipulation of the argument name leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed…
AnalizadaMedia (4.8)0.50%—Aitangbao Springboot-manager11/3/202517/6/2026
A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unknown function of the file /sysDict/add. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public…
AnalizadaMedia (4.8)0.53%—Aitangbao Springboot-manager11/3/202517/6/2026
A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue affects some unknown processing of the file /sysFiles/upload of the component Filename Handler. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely.…