Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▲ 13 respecto a la semana anterior
Críticas / altas1459▲ 323 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.6% | — | Yonyou YonbipAI | 9/1/2026 | 17/6/2026 | In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system | |
| Aplazada | Media (5.3) | 0.60% | — | Yonyou YonbipAI | 14/4/2025 | 17/6/2026 | A vulnerability was found in Yonyou YonBIP MA2.7. It has been declared as problematic. Affected by this vulnerability is the function FileInputStream of the file /mobsm/common/userfile. The manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to… | |
| Modificada | Crítica (9.8) | 0.77% | — | Yonyou Yonbip | 20/1/2024 | 9/7/2026 | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yonyou Yonbip | 20/1/2024 | 9/7/2026 | An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Crítica (9.8) | 0.98% | — | Yonyou Yonbip | 20/1/2024 | 9/7/2026 | An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component. | |
| Modificada | Crítica (9.8) | 0.77% | — | Yonyou Yonbip | 20/1/2024 | 9/7/2026 | An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Crítica (9.8) | 0.56% | — | Yonyou Yonbip | 20/1/2024 | 9/7/2026 | YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method. | |
| Modificada | Alta (7.5) | 0.51% | — | Yonyou Yonbip | 20/1/2024 | 9/7/2026 | YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component. |