Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.32% | — | Youlai-bootAI | 3/5/2026 | 17/6/2026 | A security vulnerability has been detected in youlaitech youlai-boot up to 2.21.1. This affects the function getUserList of the file src/main/java/com/youlai/boot/system/controller/UserController.java of the component Users Endpoint. Such manipulation of the argument order leads to sql injection. The attack may be… | |
| Analizada | Alta (7.1) | 0.32% | — | Youlai-boot | 22/12/2025 | 17/6/2026 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability. | |
| Analizada | Alta (7.5) | 0.44% | — | Youlai-boot | 22/12/2025 | 17/6/2026 | youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles. | |
| Analizada | Alta (7.5) | 0.34% | — | Youlai-boot | 26/11/2025 | 17/6/2026 | Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users. | |
| Analizada | Crítica (9.8) | 0.42% | — | Youlai-boot | 26/11/2025 | 17/6/2026 | Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend. |