Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.9)0.52%—Totalsuite Total Poll LiteAI25/3/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0.
AplazadaAlta (8.8)0.52%—Dokan-liteAI25/3/202617/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4.
AnalizadaMedia (4.8)0.24%—Pixelite Responsive Favicons25/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2.
AplazadaBaja (2.9)0.33%—Visualfc LiteideAI24/3/202617/6/2026
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide (liteidex/src/3rdparty/qjsonrpc/src/http-parser modules). This vulnerability is associated with program files http_parser.C. This issue affects liteide: before x38.4.
AnalizadaCrítica (9.4)1.7%⚠ Explotación activa💥 PoCAquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+123/3/202617/6/2026
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This…
AplazadaMedia (6.5)0.41%—HR Press LiteAI21/3/202617/6/2026
The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AplazadaMedia (4.3)0.19%—Uipress LiteAI21/3/202617/6/2026
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_global_settings' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers,…
AplazadaMedia (6.4)0.36%—Scoreboard FOR Html5 Games LiteAI21/3/202617/6/2026
The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small…
AplazadaMedia (6.3)0.23%—Totalsuite Totalcontest LiteAI20/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1.
AplazadaMedia (6.3)0.26%—Uipress LiteAI19/3/202617/6/2026
Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through <= 3.5.09.
Pendiente de análisisMedia (5.4)0.43%—Redhat SatelliteAIRedhat KatelloAI17/3/202617/6/2026
A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_images API endpoint. This can lead to a Denial of Service (DoS) by…
AnalizadaAlta (8.6)2.1%—Litespeedtech Litespeed WEB ServerLitespeedtech Openlitespeed16/3/202617/6/2026
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege.
AplazadaMedia (5.3)0.32%—Vowelweb VW Education LiteAI13/3/202617/6/2026
Missing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Education Lite: from n/a through <= 2.2.0.
AplazadaMedia (5.3)0.26%—Maciej BIS Permalink Manager LiteAI13/3/202617/6/2026
Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3.
AplazadaMedia (5.3)0.26%—Xpro Addons FOR Beaver Builder LiteAI13/3/202617/6/2026
Missing Authorization vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.6.
AnalizadaAlta (7.5)0.30%—Sqlite12/3/202617/6/2026
An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
Pendiente de análisisAlta (8.7)0.30%—Intelbras Telefone IP Tip200AIIntelbras Telefone IP Tip200 LiteAI11/3/202617/6/2026
IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files…
AnalizadaCrítica (9.8)0.68%—Tokuhirom Unqlite5/3/202617/6/2026
UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow.
AnalizadaAlta (7.8)1.3%⚠ Explotación activa💥 PoCQualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+2332/3/202617/6/2026
Memory corruption while using alignments for memory allocation.
AnalizadaAlta (7.8)0.07%—Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+1602/3/202617/6/2026
Memory Corruption when adding user-supplied data without checking available buffer space.
AnalizadaAlta (7.8)0.07%—Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+902/3/202617/6/2026
Memory Corruption when accessing trusted execution environment without proper privilege check.
AnalizadaAlta (7.2)0.14%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+2022/3/202617/6/2026
Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.
AnalizadaAlta (7.1)0.07%—Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+702/3/202617/6/2026
Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain.
AnalizadaAlta (7.8)0.07%—Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+1842/3/202617/6/2026
Memory Corruption when accessing buffers with invalid length during TA invocation.
AnalizadaMedia (6.5)0.11%—Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+1212/3/202617/6/2026
Transient DOS when an LTE RLC packet with invalid TB is received by UE.