Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.49% | — | R1bbit YimioaAI | 18/3/2025 | 17/6/2026 | An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file. | |
| Analizada | Media (4.2) | 0.15% | — | R1bbit Yimioa | 18/3/2025 | 17/6/2026 | yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml. | |
| Analizada | Media (6.1) | 0.19% | — | R1bbit Yimioa | 18/3/2025 | 17/6/2026 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml. | |
| Analizada | Media (6.1) | 0.19% | — | R1bbit Yimioa | 18/3/2025 | 17/6/2026 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml. | |
| Analizada | Alta (7.3) | 0.27% | — | R1bbit Yimioa | 18/3/2025 | 17/6/2026 | Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords. | |
| Analizada | Media (6.1) | 0.19% | — | R1bbit Yimioa | 18/3/2025 | 17/6/2026 | yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml. | |
| Analizada | Media (5.3) | 0.53% | — | R1bbit Yimioa | 12/2/2025 | 17/6/2026 | A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (6.9) | 0.83% | — | R1bbit Yimioa | 12/2/2025 | 17/6/2026 | A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading… | |
| Analizada | Media (5.3) | 0.38% | — | R1bbit Yimioa | 12/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be… | |
| Analizada | Media (5.3) | 0.42% | — | R1bbit Yimioa | 12/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.54% | — | R1bbit Yimioa | 12/2/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has… |