Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.54%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202610/7/2026
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
AnalizadaAlta (8.8)3.6%—Anviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary command execution (e.g., starting telnetd), resulting in root‑level access.
AnalizadaCrítica (9.8)0.81%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.
AnalizadaMedia (6.5)0.31%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and session data, which can be used to compromise the device.
AnalizadaMedia (5.3)0.42%—Anviz CX7 FirmwareAnviz CX2 Lite Firmware17/4/202617/6/2026
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/RTTY status), assisting attackers in reconnaissance against the device.
AplazadaAlta (7.5)0.25%💥 PoCRedsys Woocommerce LiteAI16/4/202617/6/2026
The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in versions up to, and including, 7.0.0 due to successful_request() handlers calculating a local signature but not validating Ds_Signature from the request before accepting payment…
AplazadaAlta (8.1)0.14%—Wpforms-liteAI15/4/202617/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Contact Form by WPForms wpforms-lite allows Cross Site Request Forgery.This issue affects Contact Form by WPForms: from n/a through <= 1.10.0.2.
AplazadaMedia (6.4)0.33%—Power Charts LiteAI15/4/202617/6/2026
The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [pc] shortcode in all versions up to, and including, 0.1.0. This is due to insufficient input sanitization and output escaping on the 'id' shortcode attribute. Specifically, in the pc_shortcode()…
ModificadaAlta (8.8)3.4%💥 ExploitLitellm10/4/202615/7/2026
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
AplazadaMedia (5.3)0.29%—Massiveshift AI Workflow Automation LiteAI8/4/202624/7/2026
Missing Authorization vulnerability in massiveshift AI Workflow Automation ai-workflow-automation-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Workflow Automation: from n/a through <= 1.4.2.
AplazadaMedia (6.5)0.25%—Totalsuite Total Poll LiteAI8/4/202624/7/2026
Missing Authorization vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Total Poll Lite: from n/a through <= 4.12.0.
AplazadaMedia (5.3)0.29%—Nmerii NM Gift Registry AND Wishlist LiteAI8/4/202624/7/2026
Missing Authorization vulnerability in nmerii NM Gift Registry and Wishlist Lite nm-gift-registry-and-wishlist-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NM Gift Registry and Wishlist Lite: from n/a through <= 5.13.
AplazadaBaja (2.7)0.28%—WP Chill Image Photo Gallery Final Tiles Grid Gallery LiteAI8/4/202624/7/2026
Authorization Bypass Through User-Controlled Key vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through <= 3.6.11.
AnalizadaAlta (7.2)0.87%—Chyrplite Chyrp Lite6/4/202624/7/2026
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the administration console that allows an administrator or a user with Change Settings permission to change the uploads path to any folder. This vulnerability allows the user to download any file on the…
AnalizadaMedia (6.5)0.30%—Chyrplite Chyrp Lite6/4/202624/7/2026
Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, an IDOR / Mass Assignment issue exists in the Post model that allows authenticated users with post editing permissions (Edit Post, Edit Draft, Edit Own Post, Edit Own Draft) to modify posts they do not own and do not have permission to edit. By…
ModificadaCrítica (9.4)0.88%💥 PoCLitellm6/4/202615/7/2026
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authentication is enabled (enable_jwt_auth: true), the OIDC userinfo cache uses token[:20] as the cache key. JWT headers produced by the same signing algorithm generate identical first 20 characters. This…
ModificadaAlta (8.7)4.0%💥 ExploitLitellm6/4/202615/7/2026
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/update endpoint does not enforce admin role authorization. A user who is already authenticated into the platform can then use this endpoint to modify proxy configuration and environment variables,…
AnalizadaAlta (7.5)0.15%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+996/4/202617/6/2026
Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood awareness network protocol connection.
AnalizadaAlta (7.5)0.20%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 Firmware+1466/4/202617/6/2026
Transient DOS when processing nonstandard FILS Discovery Frames with out-of-range action sizes during initial scans.
AnalizadaAlta (7.1)0.15%—Qualcomm Pandeiro FirmwareQualcomm Snapdragon 8 Elite GEN 5 FirmwareQualcomm Sw6100 FirmwareQualcomm Sw6100p Firmware+76/4/20267/10/2026
Cryptographic issue while copying data to a destination buffer without validating its size.
AnalizadaAlta (8.8)0.28%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1506/4/20267/10/2026
Memory corruption when decoding corrupted satellite data files with invalid signature offsets.
AnalizadaAlta (7.8)0.16%—Qualcomm Wcn3988 FirmwareQualcomm Wcn6450 FirmwareQualcomm Wcn6650 FirmwareQualcomm Wcn6755 Firmware+976/4/20267/10/2026
Memory corruption while processing a frame request from user.
AnalizadaAlta (7.8)0.16%—Qualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1776/4/20267/10/2026
Memory corruption when buffer copy operation fails due to integer overflow during attestation report generation.
Pendiente de análisisAlta (8.8)0.33%—Openbiz Cubi LiteAI26/3/202617/6/2026
OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database…
AplazadaMedia (6.4)0.36%—BWL Advanced FAQ Manager LiteAI26/3/202617/6/2026
The BWL Advanced FAQ Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'baf_sbox' shortcode in all versions up to and including 1.1.1. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'sbox_id', 'sbox_class',…
Orbitaley — Vulnerabilidades