Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2628▼ 312 respecto a la semana anterior
Críticas / altas1351▲ 89 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.26% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 25/9/2026 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component OAuth2 Client. The… | |
| Aplazada | Media (5.5) | 0.28% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 5/10/2026 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The… | |
| Aplazada | Baja (2.1) | 0.40% | — | Ruoyi-vue-proAI | 24/9/2026 | 24/9/2026 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing a manipulation can lead to path… | |
| Aplazada | Baja (2.1) | 0.26% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 29/9/2026 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing a manipulation results in cross site scripting.… | |
| Aplazada | Baja (2.1) | 0.23% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 24/9/2026 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component GoView Data Endpoint. Such… | |
| Aplazada | Baja (2.1) | 0.20% | — | Iocoder Ruoyi-vue-proAI | 24/9/2026 | 25/9/2026 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI Knowledge Module. This manipulation of the argument url causes server-side request forgery. The… | |
| Aplazada | Alta (7.1) | 0.40% | — | Ruoyi-vue-proAI | 29/6/2026 | 14/7/2026 | ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests… | |
| Aplazada | Media (5.5) | 0.65% | — | Iocoder Ruoyi-vue-proAI | 29/6/2026 | 29/6/2026 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java of the component AppFileController File Upload Endpoint.… | |
| Aplazada | Media (5.5) | 0.65% | — | Ruoyi Vue-proAIIocoder Yudao-cloudAI | 4/5/2026 | 17/6/2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitation of the attack is… | |
| Analizada | Baja (2.1) | 0.32% | — | Iocoder Ruoyi-vue-pro | 26/9/2025 | 17/6/2026 | A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early… | |
| Analizada | Baja (2.1) | 0.33% | — | Iocoder Ruoyi-vue-pro | 12/9/2025 | 17/6/2026 | A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has been published and may be used. The… | |
| Analizada | Baja (2.1) | 0.33% | — | Iocoder Ruoyi-vue-pro | 12/9/2025 | 17/6/2026 | A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.73% | — | Iocoder Ruoyi-vue-pro | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. It is possible to launch the… | |
| Analizada | Media (5.3) | 0.87% | — | Iocoder Ruoyi-vue-pro | 25/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack… | |
| Analizada | Media (5.3) | 0.87% | — | Iocoder Ruoyi-vue-pro | 25/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload Interface. The manipulation of the argument File leads to path traversal. The attack can be initiated… | |
| Analizada | Media (5.3) | 0.92% | — | Iocoder Ruoyi-vue-pro | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component Backend File Upload Interface. The manipulation of the argument path leads to path traversal. It is possible to initiate the attack… | |
| Analizada | Media (5.3) | 0.92% | — | Iocoder Ruoyi-vue-pro | 24/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload of the component Front-End Store Interface. The manipulation of the argument path leads to path traversal. The attack may… | |
| Analizada | Media (5.3) | 0.49% | — | Iocoder Ruoyi-vue-pro | 6/3/2025 | 17/6/2026 | A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.95% | — | Iocoder Ruoyi-vue-pro | 25/8/2022 | 17/6/2026 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. |