Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.47% | 💥 PoC | Bishopfox Sliver | 31/3/2026 | 24/7/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or… | |
| Aplazada | Alta (7.5) | 0.33% | — | Tychesoftwares Woocommerce Delivery NotesAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocommerce-delivery-notes allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through <= 5.9.0. | |
| Analizada | Crítica (9.3) | 4.0% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 23/3/2026 | 17/6/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | |
| Analizada | Media (5.7) | 0.44% | 💥 PoC | Bishopfox Sliver | 20/3/2026 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remote OOM (Out-of-Memory) vulnerability in the Sliver C2 server's mTLS and WireGuard C2 transport layer. The socketReadEnvelope and socketWGReadEnvelope functions trust an attacker-controlled 4-byte… | |
| Modificada | Media (6.5) | 0.27% | 💥 PoC | Asseco Live | 12/3/2026 | 5/7/2026 | Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the host via "path" parameter in the downloadAttachment and downloadAttachmentFromPath API calls. | |
| Analizada | Alta (7.1) | 0.48% | — | Olivetin | 11/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live EventStream broadcasts execution events and action output to authenticated dashboard subscribers without enforcing per-action authorization. A low-privileged authenticated user can receive output from… | |
| Aplazada | Crítica (9.9) | 0.48% | 💥 PoC | Asseco SEE LiveAI | 11/3/2026 | 5/7/2026 | Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachments via a computable URL. | |
| Aplazada | Crítica (9.8) | 0.80% | 💥 PoC | Datalogics Ecommerce DeliveryAI | 11/3/2026 | 17/6/2026 | The Datalogics Ecommerce Delivery WordPress plugin before 2.6.60 exposes an unauthenticated REST endpoint that allows any remote user to modify the option `datalogics_token` without verification. This token is subsequently used for authentication in a protected endpoint that allows users to perform arbitrary WordPress… | |
| Analizada | Alta (8.5) | 0.95% | — | Olivetin | 10/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists execution log entries to disk. The filename used for these log files is constructed in part from the user-supplied UniqueTrackingId field in the StartAction API request.… | |
| Analizada | Baja (2.1) | 0.54% | 💥 PoC | Bishopfox Sliver | 7/3/2026 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vulnerability exists in the Sliver C2 server's Protobuf unmarshalling logic due to a systemic lack of nil-pointer validation. By extracting valid implant credentials and omitting nested fields in a… | |
| Analizada | Media (4.3) | 0.51% | — | Olivetin | 6/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authorization flaw in OliveTin allows authenticated users with view: false permission to enumerate action bindings and metadata via dashboard and API endpoints. Although execution (exec) may be correctly denied, the… | |
| Analizada | Media (4.3) | 0.60% | 💥 PoC | Olivetin | 6/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication context confusion vulnerability in RestartAction allows a low‑privileged authenticated user to execute actions they are not permitted to run. RestartAction constructs a new internal connect.Request… | |
| Analizada | Media (5.4) | 0.40% | — | Olivetin | 6/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not revoke server-side sessions when a user logs out. Although the browser cookie is cleared, the corresponding session remains valid in server storage until expiry (default ≈ 1 year). An attacker with a… | |
| Analizada | Alta (8.8) | 0.32% | — | Olivetin | 6/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentication is configured using either "authJwtPubKeyPath" (local RSA public key) or "authJwtHmacSecret" (HMAC secret), the configured audience value (authJwtAud) is not enforced during token parsing. As a… | |
| Aplazada | Alta (8.8) | 0.21% | — | Alive ParishAI | 6/3/2026 | 17/6/2026 | Alive Parish 2.0.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the key parameter in the search endpoint. Attackers can also upload arbitrary files via the person photo upload functionality to the images/uploaded… | |
| Analizada | Alta (7.5) | 0.81% | — | Olivetin | 5/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.0, OliveTin allows an unauthenticated guest to terminate running actions through KillAction even when authRequireGuestsToLogin: true is enabled. Guests are correctly blocked from dashboard access, but can still call the… | |
| Analizada | Alta (7.5) | 0.49% | — | Olivetin | 5/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated denial-of-service vulnerability exists in OliveTin’s OAuth2 login flow. Concurrent requests to /oauth/login can trigger unsynchronized access to a shared registeredStates map, causing a Go runtime… | |
| Analizada | Alta (7.5) | 0.81% | — | Olivetin | 5/3/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By issuing multiple parallel requests, an attacker can exhaust… | |
| Aplazada | Media (6.4) | 0.19% | — | Livemesh Addons FOR Beaver BuilderAI | 26/2/2026 | 17/6/2026 | The Livemesh Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `[labb_pricing_item]` shortcode's `title` and `value` attributes in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. Specifically, the plugin uses… | |
| Analizada | Media (4.9) | 0.34% | — | Livehelperchat Live Helper Chat | 26/2/2026 | 17/6/2026 | Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats… | |
| Aplazada | Alta (8.8) | 0.38% | 💥 PoC | LivecodeAI | 25/2/2026 | 17/6/2026 | LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveCode's `i18n-update-pull` GitHub Actions workflow is vulnerable to JavaScript injection. The title of the Pull Request associated with the triggering issue comment is interpolated directly into a… | |
| Analizada | Media (5.5) | 0.61% | — | Clive 21 News Portal Project | 25/2/2026 | 17/6/2026 | A vulnerability was found in itsourcecode News Portal Project 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. | |
| Analizada | Crítica (9.9) | 0.65% | 💥 PoC | Olivetin | 25/2/2026 | 17/6/2026 | OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed argument can inject shell metacharacters… | |
| Analizada | Media (5.5) | 0.59% | — | Clive 21 News Portal Project | 25/2/2026 | 17/6/2026 | A weakness has been identified in itsourcecode News Portal Project 1.0. The impacted element is an unknown function of the file /admin/add-category.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.5) | 0.59% | — | Clive 21 News Portal Project | 25/2/2026 | 17/6/2026 | A security flaw has been discovered in itsourcecode News Portal Project 1.0. The affected element is an unknown function of the file /newsportal/admin/edit-category.php. The manipulation of the argument Category results in sql injection. The attack may be performed from remote. The exploit has been released to the… |