Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.78%—Redhat SatelliteLogicminds Rubyipmi27/2/202617/6/2026
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution…
ModificadaMedia (6.5)0.35%—Theforeman ForemanRedhat SatelliteRedhat Satellite CapsuleRedhat Enterprise Linux27/2/202617/6/2026
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
AnalizadaAlta (7.5)0.55%—Morelitea Initiative26/2/202617/6/2026
Initiative is a self-hosted project management platform. An access control vulnerability exists in Initiative versions prior to 0.32.2 where uploaded documents are served from a publicly accessible /uploads/ directory without any authentication or authorization checks. Any uploaded file can be accessed directly via…
AnalizadaAlta (8.1)0.39%—Morelitea Initiative26/2/202617/6/2026
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate previously issued JWT access tokens after a user changes their password. As a result, older tokens remain valid until expiration and can still be used to access protected API endpoints. This behavior…
AnalizadaAlta (8.7)0.56%—Morelitea Initiative26/2/202617/6/2026
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 are vulnerable to Stored Cross-Site Scripting (XSS) in the document upload functionality. Any user with upload permissions within the "Initiatives" section can upload a malicious `.html` or `.htm` file as a document.…
AplazadaCrítica (9.3)1.1%💥 ExploitElementskit LiteAI23/2/202617/6/2026
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and…
AplazadaAlta (7.5)0.30%—Pixelite WP FullcalendarAI20/2/202617/6/2026
Missing Authorization vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP FullCalendar: from n/a through <= 1.6.
AplazadaAlta (7.5)0.34%—Mdalabar WOO Order Delivery Time LiteAI20/2/202617/6/2026
Authentication Bypass by Spoofing vulnerability in mdalabar WooODT Lite byconsole-woo-order-delivery-time allows Identity Spoofing.This issue affects WooODT Lite: from n/a through <= 2.5.2.
AplazadaAlta (7.5)0.30%—Xlplugins Nextmove LiteAI20/2/202617/6/2026
Missing Authorization vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0.
AplazadaMedia (6.5)0.25%—Litespeed Technologies Litespeed CacheAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Stored XSS.This issue affects LiteSpeed Cache: from n/a through <= 6.5.2.
AplazadaAlta (7.5)0.35%—Product Table AND List Builder FOR Woocommerce LiteAI19/2/202617/6/2026
The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection via the 'search' parameter in all versions up to, and including, 4.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
AplazadaMedia (4.3)0.25%—Official-mailerlite-sign-up-formsAI19/2/202617/6/2026
Missing Authorization vulnerability in MailerLite MailerLite official-mailerlite-sign-up-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MailerLite: from n/a through <= 1.7.18.
AplazadaMedia (5.3)0.24%—Wplab Wp-lister Lite FOR EbayAI19/2/202617/6/2026
Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.8.5.
AplazadaMedia (5.3)0.24%—Wpdeveloper Essential Addons FOR Elementor LiteAI19/2/202617/6/2026
Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.5.
AplazadaMedia (6.1)0.47%💥 ExploitFrontend Post Submission Manager LiteAI18/2/202617/6/2026
The Frontend Post Submission Manager Lite plugin for WordPress is vulnerable to Open Redirection in all versions up to, and including, 1.2.7 due to insufficient validation on the 'requested_page' POST parameter in the verify_username_password function. This makes it possible for unauthenticated attackers to redirect…
AplazadaAlta (7.5)0.36%—TON Lite ServerAI13/2/202617/6/2026
A Denial of Service (DoS) vulnerability was discovered in the TON Lite Server before v2024.09. The vulnerability arises from the handling of external arguments passed to locally executed "get methods." An attacker can inject a constructed Continuation object (an internal TVM type) that is normally restricted within…
AnalizadaAlta (8.8)0.46%—Lavalite13/2/202617/6/2026
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based…
AplazadaCrítica (9.4)0.39%—E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI11/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record…
AplazadaMedia (6.4)0.27%—OpenposliteAI11/2/202617/6/2026
The OpenPOS Lite – Point of Sale for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'width' parameter of the order_qrcode shortcode in all versions up to, and including, 3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaMedia (6.5)0.57%—Litestar9/2/202617/6/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileStore is used as response-cache backend, an unauthenticated remote attacker can…
AnalizadaMedia (6.5)0.46%—Litestar9/2/202617/6/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker…
AnalizadaMedia (6.5)0.54%—Litestar9/2/202617/6/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used with fullmatch() for validation. Because metacharacters are not escaped, a malicious origin can match unexpectedly. The…
AplazadaMedia (6.7)0.44%—Coreftp Core FTP LiteAI7/2/202617/6/2026
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction.
AplazadaBaja (2.1)0.27%—Isaacwasserman MCP Vegalite ServerAI6/2/202617/6/2026
A security vulnerability has been detected in isaacwasserman mcp-vegalite-server up to 16aefed598b8cd897b78e99b907f6e2984572c61. Affected by this vulnerability is the function eval of the component visualize_data. Such manipulation of the argument vegalite_specification leads to code injection. The attack may be…
AnalizadaMedia (6.5)0.16%—Qualcomm Sa8620p FirmwareQualcomm Sa8770p FirmwareQualcomm Sa9000p FirmwareQualcomm Sar2130p Firmware+902/2/202617/6/2026
Transient DOS when processing a received frame with an excessively large authentication information element.