Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.54% | — | ThymeleafAI | 12/5/2026 | 17/6/2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Prior to 3.1.5.RELEASE, a security bypass vulnerability exists in the expression execution mechanisms of Thymeleaf. Although the library provides mechanisms to avoid the execution of potentially dangerous expressions in some specific… | |
| Modificada | Crítica (9) | 1.2% | — | Thymeleaf | 17/4/2026 | 18/8/2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly neutralize specific… | |
| Modificada | Crítica (9) | 0.94% | — | Thymeleaf | 17/4/2026 | 4/8/2026 | Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanisms to prevent expression injection, it fails to properly restrict the scope of… | |
| Modificada | Alta (7.5) | 0.97% | — | Codecentric Spring Boot AdminThymeleaf | 14/7/2023 | 17/6/2026 | Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML. This may be relevant for SSTI (Server Side Template Injection) and code execution in spring-boot-admin if MailNotifier is enabled and there is write access to… | |
| Modificada | Crítica (9.8) | 4.0% | — | Thymeleaf | 9/11/2021 | 17/6/2026 | In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. | |
| Modificada | Media (4.3) | 1.4% | — | Extrosoft Thyme | 6/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the callback parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Extrosoft Thyme | 11/2/2009 | 16/6/2026 | Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Extrosoft COM Thyme | 11/2/2009 | 16/6/2026 | SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | — | Extrovert Software Thyme | 7/10/2008 | 16/6/2026 | SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.5% | — | Extrovert Software Thyme Calndar | 11/5/2007 | 16/6/2026 | SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL commands via the eid parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Extrosoft Thyme | 1/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Thyme 1.3 allows remote attackers to inject arbitrary web script or HTML via the search page. |