Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

699 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.6)0.39%—Areoi ALL Bootstrap BlocksAI18/9/202618/9/2026
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file…
AplazadaMedia (6.8)0.43%—Areoi ALL Bootstrap BlocksAI18/9/202618/9/2026
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not properly escape a block attribute before outputting it in HTML tag-name position, allowing users with Contributor-level access and above to inject arbitrary web scripts that execute when the affected content is viewed.
AplazadaBaja (2.1)0.24%—PbootcmsAI16/9/202616/9/2026
A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to cross-site request forgery. The attack may be…
AplazadaBaja (2)0.35%—PbootcmsAI16/9/202618/9/2026
A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross site scripting. The attack is possible to be carried out remotely.…
AplazadaMedia (4.3)0.28%—Smartadmin APIAIOracle JavaAIVmware Spring BootAI15/9/202622/9/2026
SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged employee to retrieve employee records…
AplazadaBaja (2.1)0.39%—Jaygajera17 E-commerce-project-springbootAI13/9/202616/9/2026
A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipulation of the argument userid results in authorization bypass. It is possible to…
AplazadaMedia (5.1)0.36%—Maliangnansheng Bbs-springbootAI13/9/202616/9/2026
A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.
AplazadaAlta (7.8)0.84%—Tubitak Bilgem Pardus Boot RepairAI11/9/202611/9/2026
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.
AplazadaMedia (4.1)0.15%—Live-bootAI11/9/202622/9/2026
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
AplazadaMedia (4.3)0.29%—PbootcmsAI9/9/202614/9/2026
SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.
AplazadaMedia (4.3)0.37%—Bootstrapped WP Recipe MakerAI9/9/20269/9/2026
The WP Recipe Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaCrítica (9.1)0.51%—Springboot-projectAI8/9/20269/9/2026
Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without authentication.
Pendiente de análisisAlta (7.5)0.11%—McubootAI7/9/20269/9/2026
When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that if there is at least a single slot for each image available, the system is…
AplazadaBaja (2.1)0.39%—JeecgbootAI6/9/20268/9/2026
A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. Such manipulation of the argument credential leads to…
AplazadaMedia (6.5)0.38%—JeecgbootAI4/9/20268/9/2026
JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, queryUserById, and queryUsersByIds) to retrieve sensitive information of…
AplazadaMedia (6.4)0.26%—Bootstrapped WP Recipe MakerAI1/9/20261/9/2026
The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaBaja (2.1)0.35%—Dibo-software DibootAI31/8/202631/8/2026
A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing a manipulation of the argument tenantId can lead to improper access controls. The attack may be launched remotely. The exploit…
AplazadaBaja (2.1)0.35%—Dibo-software DibootAI31/8/20262/9/2026
A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a manipulation of the argument tenantId results in improper access controls. The attack may be initiated remotely. The…
AplazadaBaja (2.1)0.36%—Dibo-software DibootAI31/8/202631/8/2026
A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The exploit has been disclosed to the public…
AplazadaAlta (7.8)0.49%—Tubitak Bilgem Pardus Boot RepairAI31/8/20261/9/2026
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: from 1.0.7 before 1.0.8.
AplazadaBaja (2)0.43%—Jeecgboot Jeewx-bootAI31/8/202631/8/2026
A vulnerability was determined in jeecgboot jeewx-boot up to 641ab52c3e1845fec39996d7794c33fb40dad1dd. This issue affects the function MyJwWebJwid3Controller.doUpload of the file jeewx-boot-module-weixin/src/main/java/com/jeecg/p3/open/web/back/MyJwWebJwid3Controller.java of the component doUpload Endpoint. Executing…
AplazadaBaja (1.3)0.31%—Lognet Grpc-spring-boot-starterAI31/8/202631/8/2026
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability…
Pendiente de análisisMedia (6.9)0.45%—ZipkinAIVmware Spring BootAI28/8/202624/9/2026
Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator endpoints, or modify log levels to suppress…
AplazadaCrítica (9.8)1.1%—JeecgbootAI26/8/20261/9/2026
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this blacklist to be completely bypassed through…
AplazadaCrítica (9.8)0.82%—Denx U-bootAI26/8/20269/9/2026
An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_bgdtable, the size calculation can lead to under allocation and this underallocated buffer will be used in memcpy() which could lead to arbitrary code execution, a denial of service, or other…