Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.9) | 0.52% | — | Totalsuite Total Poll LiteAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in TotalSuite Total Poll Lite totalpoll-lite allows Remote Code Inclusion.This issue affects Total Poll Lite: from n/a through <= 4.12.0. | |
| Aplazada | Alta (8.8) | 0.52% | — | Dokan-liteAI | 25/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc. Dokan dokan-lite allows Authentication Abuse.This issue affects Dokan: from n/a through <= 4.2.4. | |
| Analizada | Media (4.8) | 0.24% | — | Pixelite Responsive Favicons | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Responsive Favicons allows Cross-Site Scripting (XSS).This issue affects Responsive Favicons: from 0.0.0 before 2.0.2. | |
| Aplazada | Baja (2.9) | 0.33% | — | Visualfc LiteideAI | 24/3/2026 | 17/6/2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in visualfc liteide (liteidex/src/3rdparty/qjsonrpc/src/http-parser modules). This vulnerability is associated with program files http_parser.C. This issue affects liteide: before x38.4. | |
| Analizada | Crítica (9.4) | 1.7% | ⚠ Explotación activa💥 PoC | Aquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+1 | 23/3/2026 | 17/6/2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This… | |
| Aplazada | Media (6.5) | 0.41% | — | HR Press LiteAI | 21/3/2026 | 17/6/2026 | The Hr Press Lite plugin for WordPress is vulnerable to unauthorized access of sensitive employee data due to a missing capability check on the `hrp-fetch-employees` AJAX action in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (4.3) | 0.19% | — | Uipress LiteAI | 21/3/2026 | 17/6/2026 | The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'uip_save_global_settings' function in all versions up to, and including, 3.5.09. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.36% | — | Scoreboard FOR Html5 Games LiteAI | 21/3/2026 | 17/6/2026 | The Scoreboard for HTML5 Games Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'scoreboard' shortcode in all versions up to, and including, 1.2. The shortcode function sfhg_shortcode() allows arbitrary HTML attributes to be added to the rendered <iframe> element, with only a small… | |
| Aplazada | Media (6.3) | 0.23% | — | Totalsuite Totalcontest LiteAI | 20/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injection.This issue affects TotalContest Lite: from n/a through <= 2.9.1. | |
| Aplazada | Media (6.3) | 0.26% | — | Uipress LiteAI | 19/3/2026 | 17/6/2026 | Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: from n/a through <= 3.5.09. | |
| Pendiente de análisis | Media (5.4) | 0.43% | — | Redhat SatelliteAIRedhat KatelloAI | 17/3/2026 | 17/6/2026 | A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_images API endpoint. This can lead to a Denial of Service (DoS) by… | |
| Analizada | Alta (8.6) | 2.1% | — | Litespeedtech Litespeed WEB ServerLitespeedtech Openlitespeed | 16/3/2026 | 17/6/2026 | OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An arbitrary OS command may be executed by an attacker with the administrative privilege. | |
| Aplazada | Media (5.3) | 0.32% | — | Vowelweb VW Education LiteAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in vowelweb VW Education Lite vw-education-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects VW Education Lite: from n/a through <= 2.2.0. | |
| Aplazada | Media (5.3) | 0.26% | — | Maciej BIS Permalink Manager LiteAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Permalink Manager Lite: from n/a through < 2.5.3. | |
| Aplazada | Media (5.3) | 0.26% | — | Xpro Addons FOR Beaver Builder LiteAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Xpro Xpro Addons For Beaver Builder – Lite xpro-addons-beaver-builder-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Xpro Addons For Beaver Builder – Lite: from n/a through <= 1.5.6. | |
| Analizada | Alta (7.5) | 0.30% | — | Sqlite | 12/3/2026 | 17/6/2026 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | |
| Pendiente de análisis | Alta (8.7) | 0.30% | — | Intelbras Telefone IP Tip200AIIntelbras Telefone IP Tip200 LiteAI | 11/3/2026 | 17/6/2026 | IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files… | |
| Analizada | Crítica (9.8) | 0.68% | — | Tokuhirom Unqlite | 5/3/2026 | 17/6/2026 | UnQLite versions through 0.06 for Perl uses a potentially insecure version of the UnQLite library. UnQLite for Perl embeds the UnQLite library. Version 0.06 and earlier of the Perl module uses a version of the library from 2014 that may be vulnerable to a heap-based overflow. | |
| Analizada | Alta (7.8) | 1.3% | ⚠ Explotación activa💥 PoC | Qualcomm Sm7675p FirmwareQualcomm Sm8475p FirmwareQualcomm Sm8550p FirmwareQualcomm Sm8635 Firmware+233 | 2/3/2026 | 17/6/2026 | Memory corruption while using alignments for memory allocation. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+160 | 2/3/2026 | 17/6/2026 | Memory Corruption when adding user-supplied data without checking available buffer space. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Sa8295p FirmwareQualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p Firmware+90 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing trusted execution environment without proper privilege check. | |
| Analizada | Alta (7.2) | 0.14% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem FirmwareQualcomm Apq8098 Firmware+202 | 2/3/2026 | 17/6/2026 | Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. | |
| Analizada | Alta (7.1) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+70 | 2/3/2026 | 17/6/2026 | Cryptographic Issue when a shared VM reference allows HLOS to boot loader and access cert chain. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Fastconnect 7800 FirmwareQualcomm FWA GEN 3 Ultra FirmwareQualcomm G1 GEN 1 FirmwareQualcomm G2 GEN 1 Firmware+184 | 2/3/2026 | 17/6/2026 | Memory Corruption when accessing buffers with invalid length during TA invocation. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+121 | 2/3/2026 | 17/6/2026 | Transient DOS when an LTE RLC packet with invalid TB is received by UE. |