Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.23% | — | Tianti Project Tianti | 1/9/2025 | 17/6/2026 | A vulnerability has been found in xujeff tianti 天梯 up to 2.3. The impacted element is the function ajaxUploadFile of the file src/main/java/com/jeff/tianti/controller/UploadController.java. The manipulation of the argument upfile leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit… | |
| Aplazada | Baja (2.1) | 0.29% | — | Xujeff TiantiAI | 10/8/2025 | 17/6/2026 | A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to csv injection. The attack may be initiated remotely. The exploit… | |
| Analizada | Baja (2.1) | 0.38% | — | Tianti Project Tianti | 10/8/2025 | 17/6/2026 | A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been declared as critical. This vulnerability affects unknown code of the file /tianti-module-admin/user/ajax/save. The manipulation leads to missing authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Alta (8) | 0.22% | — | Tianti Project Tianti | 10/3/2025 | 17/6/2026 | tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/upd/status. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request. | |
| Analizada | Media (5.4) | 0.27% | — | Tianti Project Tianti | 10/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in tianti v2.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the coverImageURL parameter at /article/ajax/save. | |
| Analizada | Alta (8.8) | 0.23% | — | Tianti Project Tianti | 10/3/2025 | 17/6/2026 | tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request. | |
| Modificada | Media (6.5) | 1.2% | — | Tianti Project Tianti | 8/11/2018 | 17/6/2026 | The skin-management feature in tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/user/skin/list directly because controller\usercontroller.java maps a /skin/list request to the function skinList, and lacks an authorization check. | |
| Modificada | Alta (8.8) | 1.8% | — | Tianti Project Tianti | 8/11/2018 | 17/6/2026 | tianti 2.3 allows remote authenticated users to bypass intended permission restrictions by visiting tianti-module-admin/cms/column/list directly to read the column list page or edit a column. | |
| Modificada | Media (5.4) | 0.67% | — | Tianti Project Tianti | 7/11/2018 | 17/6/2026 | tianti 2.3 has reflected XSS in the user management module via the tianti-module-admin/user/list userName parameter. | |
| Modificada | Media (5.4) | 0.67% | — | Tianti Project Tianti | 7/11/2018 | 17/6/2026 | tianti 2.3 has stored XSS in the article management module via an article title. | |
| Modificada | Media (5.4) | 0.67% | — | Tianti Project Tianti | 7/11/2018 | 17/6/2026 | tianti 2.3 has stored XSS in the userlist module via the tianti-module-admin/user/ajax/save_role name parameter, which is mishandled in tianti-module-admin\src\main\webapp\WEB-INF\views\user\user_list.jsp. | |
| Modificada | Media (5.4) | 0.27% | — | Zhtiantian Kuailecaidengmi | 30/9/2014 | 17/6/2026 | The kuailecaidengmi (aka com.licai.kuailecaidengmi) application 1.7.12.15 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Zhtiantian Challengertx | 23/9/2014 | 17/6/2026 | The ChallengerTX (aka com.zhtiantian.ChallengerTX) application 3.9.12.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 1.4% | — | Xixuntiantian | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the XiXunTianTian (com.xixun.tiantian) application 0.6.2 beta for Android has unknown impact and attack vectors. |