Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.25% | — | Guchengwuyue YshopmallAI | 9/9/2026 | 14/9/2026 | yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files. | |
| Analizada | Baja (2.1) | 0.34% | — | Guchengwuyue Yshopmall | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in guchengwuyue yshopmall up to 1.9.1. This affects the function updateAvatar of the file /api/users/updateAvatar of the component co.yixiang.utils.FileUtil. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Modificada | Baja (2.1) | 0.39% | — | Guchengwuyue Yshopmall | 9/1/2026 | 17/6/2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the… | |
| Analizada | Alta (7.2) | 0.44% | — | Guchengwuyue Yshopmall | 4/3/2025 | 17/6/2026 | yshopmall <=v1.9.0 is vulnerable to SQL Injection in the image listing interface. | |
| Analizada | Crítica (9.8) | 1.0% | — | Guchengwuyue Yshopmall | 15/11/2024 | 17/6/2026 | yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files. |