Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.39% | — | Router-for-me Cliproxyapi | 7/5/2026 | 17/6/2026 | A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API Interface. The manipulation of the argument url leads to server-side request forgery. Remote exploitation of the attack… | |
| Modificada | Media (5.4) | 0.19% | — | Ymfe Yapi | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in YMFE yapi v1.12.0. | |
| Analizada | Alta (7.5) | 0.34% | — | Ymfe Yapi | 9/3/2026 | 17/6/2026 | An issue pertaining to CWE-400: Uncontrolled Resource Consumption was discovered in YMFE yapi v1.12.0 and allows attackers to cause a denial of service. | |
| Analizada | Alta (7.4) | 0.18% | — | Ymfe Yapi | 23/2/2026 | 17/6/2026 | An issue pertaining to CWE-295: Improper Certificate Validation was discovered in YMFE yapi v1.12.0. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in the HTTPS agent configuration for Axios requests | |
| Modificada | Media (4.3) | 0.26% | — | Jenkins Readyapi Functional Testing | 9/7/2025 | 17/6/2026 | Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Media (6.5) | 0.39% | — | Jenkins Readyapi Functional Testing | 9/7/2025 | 17/6/2026 | Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Aplazada | Alta (7.4) | 0.49% | — | Ymfe YapiAI | 30/4/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Advanced Expectation - Response module of yapi v1.10.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the body field. | |
| Modificada | Media (5.4) | 0.54% | — | Ymfe Yapi | 26/1/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api edit page. | |
| Modificada | Media (5.1) | 0.34% | — | Ymfe Yapi | 1/3/2021 | 17/6/2026 | Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tokens. This occurs because Math.random in Node.js is used. | |
| Modificada | Crítica (9.8) | 13% | — | Smartbear Readyapi | 20/5/2020 | 17/6/2026 | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component. | |
| Modificada | Alta (7.8) | 4.8% | — | Smartbear ReadyapiSmartbear Soapui | 5/2/2020 | 17/6/2026 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious… | |
| Modificada | Alta (8.8) | 9.8% | — | Smartbear Readyapi | 3/5/2019 | 17/6/2026 | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | |
| Modificada | Media (5.4) | 0.67% | — | Ymfe Yapi | 28/9/2018 | 17/6/2026 | An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project. | |
| Modificada | Alta (7.5) | 2.0% | — | Getcityapi.yoehoehne Project Getcityapi.yoehoehne | 7/6/2018 | 17/6/2026 | getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.8) | 3.6% | — | Pyanyapi Project Pyanyapi | 8/11/2017 | 17/6/2026 | An exploitable vulnerability exists in the YAML parsing functionality in the YAMLParser method in Interfaces.py in PyAnyAPI before 0.6.1. A YAML parser can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into… | |
| Modificada | Media (6.8) | 1.2% | — | Yapig | 18/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in sample.php in YaPiG 0.95b allows remote attackers to execute arbitrary PHP code via a URL in the YAPIG_PATH parameter. NOTE: this issue has been disputed by CVE, since YAPIG_PATH is defined before use | |
| Modificada | Media (4.3) | 1.7% | — | Yapig | 29/8/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers to inject arbitrary web script or HTML via the D_REFRESH_URL parameter. | |
| Modificada | Alta (9) | 2.2% | — | Yapig | 31/12/2005 | 16/6/2026 | Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via the TestGallery parameter in a mod_info action to modify_gallery.php, which inserts the code into guid_info.php. NOTE: this issue is easier… | |
| Modificada | Alta (7.5) | 1.7% | — | Yapig | 31/12/2005 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a logged-in user, as demonstrated by tricking the administrator to access a web page that performs a mod_info action in modify_gallery.php. | |
| Modificada | Media (5.1) | 6.9% | — | Yapig | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the Homepage field (aka the Website field) in an "image-related comment" and (2) the img_size field in view.php. NOTE: due to lack of… | |
| Modificada | Media (4.3) | 1.3% | — | Yapig | 30/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in YaPig 0.95 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | |
| Modificada | Media (6.4) | 2.6% | — | Yapig | 9/6/2005 | 16/6/2026 | Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Yapig | 9/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Yapig | 9/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment. | |
| Modificada | Media (5) | 1.5% | — | Yapig | 9/6/2005 | 16/6/2026 | global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter. |