Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.23%—Tianti Project Tianti1/9/202517/6/2026
A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit…
AplazadaBaja (2.1)0.29%—Xujeff TiantiAI10/8/202517/6/2026
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to csv injection. The attack may be initiated remotely. The exploit…
AnalizadaBaja (2.1)0.38%—Tianti Project Tianti10/8/202517/6/2026
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tianti-module-admin/user/ajax/save. The manipulation leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may…
AnalizadaAlta (8)0.22%—Tianti Project Tianti10/3/202517/6/2026
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.
AnalizadaMedia (5.4)0.27%—Tianti Project Tianti10/3/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save.
AnalizadaAlta (8.8)0.23%—Tianti Project Tianti10/3/202517/6/2026
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.
ModificadaMedia (6.5)1.2%—Tianti Project Tianti8/11/201817/6/2026
The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check.
ModificadaAlta (8.8)1.8%—Tianti Project Tianti8/11/201817/6/2026
tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column.
ModificadaMedia (5.4)0.67%—Tianti Project Tianti7/11/201817/6/2026
tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter.
ModificadaMedia (5.4)0.67%—Tianti Project Tianti7/11/201817/6/2026
tianti 2.3 has stored XSS in the article management module via an article title.
ModificadaMedia (5.4)0.67%—Tianti Project Tianti7/11/201817/6/2026
tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\views\user\user_list.jsp.
ModificadaMedia (5.4)0.27%—Zhtiantian Kuailecaidengmi30/9/201417/6/2026
The kuailecaidengmi (aka com.licai.kuailecaidengmi) application 1.7.12.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Zhtiantian Challengertx23/9/201417/6/2026
The ChallengerTX (aka com.zhtiantian.ChallengerTX) application 3.9.12.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (10)1.4%—Xixuntiantian7/3/201216/6/2026
Unspecified vulnerability in the XiXunTianTian (com.xixun.tiantian) application 0.6.2 beta for Android has unknown impact and attack vectors.