Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.16% | — | Livemesh Addons FOR Beaver BuilderAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Beaver Builder addons-for-beaver-builder allows Stored XSS.This issue affects Livemesh Addons for Beaver Builder: from n/a through <= 3.9.2. | |
| Modificada | Crítica (9.3) | 0.65% | — | Ateme Flamingo XL FirmwareAteme Flamingo XS FirmwareAteme SoapliveAteme Soapsystem | 30/12/2025 | 24/9/2026 | Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without complex authentication mechanisms. | |
| Aplazada | Media (5.3) | 0.21% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in tychesoftwares Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Live Composer Page BuilderAI | 24/12/2025 | 21/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 2.1.22. | |
| Aplazada | Crítica (9.8) | 3.7% | 💥 Exploit | Woocommerce Delivery NotesAI | 24/12/2025 | 17/6/2026 | The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 5.8.0 via the 'WooCommerce_Delivery_Notes::update' function. This is due to missing capability check in the 'WooCommerce_Delivery_Notes::update' function, PHP enabled in… | |
| Aplazada | Media (5.3) | 0.27% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 23/12/2025 | 17/6/2026 | Vulnerability in Tyche softwares Product Delivery Date for WooCommerce – Lite.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.0. | |
| Aplazada | Alta (7.5) | 0.62% | — | Live ComposerAI | 21/12/2025 | 17/6/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.2 via deserialization of untrusted input in the dslc_module_posts_output shortcode. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Modificada | Crítica (9.1) | 0.36% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Modificada | Alta (7.1) | 0.15% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Media (5.4) | 0.18% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not respond in… | |
| Aplazada | Media (6.4) | 0.23% | — | Live ComposerAI | 17/12/2025 | 17/6/2026 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to multiple Stored Cross-Site Scripting vulnerabilities via DOM manipulation in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Analizada | Crítica (9.3) | 1.2% | ⚠ Explotación activa | Asus Live Update | 17/12/2025 | 25/9/2026 | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions… | |
| Aplazada | Media (6.4) | 0.22% | — | Livemesh Siteorigin WidgetsAI | 13/12/2025 | 7/10/2026 | The Livemesh SiteOrigin Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Hero Header and Pricing Table widgets in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.23% | — | Tychesoftwares Order Delivery Date FOR WoocommerceAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Delivery Date for WooCommerce: from n/a through <= 4.3.1. | |
| Aplazada | Media (4.3) | 0.22% | — | Live CSS PreviewAI | 5/12/2025 | 17/6/2026 | The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_frontend_save' AJAX endpoint in all versions up to, and including, 2.1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update… | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the MPEG1or2Demux::newElementaryStream() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG Program stream. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A NULL pointer dereference in the ADTSAudioFileServerMediaSubsession::createNewRTPSink() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A heap overflow in the MatroskaFile::createRTPSinkForTrackNumber() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MKV file. | |
| Analizada | Media (6.5) | 0.30% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A use-after-free in the ADTSAudioFileSource::samplingFrequency() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via supplying a crafted ADTS/AAC file. | |
| Analizada | Media (6.5) | 0.33% | — | Live555 Streaming Media | 1/12/2025 | 17/6/2026 | A buffer overflow in the getSideInfo2() function of Live555 Streaming Media v2018.09.02 allows attackers to cause a Denial of Service (DoS) via a crafted MP3 stream. | |
| Aplazada | Alta (7.5) | 0.31% | — | Live Sales Notification FOR WoocommerceAI | 18/11/2025 | 17/6/2026 | The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes… | |
| Aplazada | Media (6.4) | 0.18% | — | Live PhotosAI | 11/11/2025 | 17/6/2026 | The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_src', 'img_src', and 'class' parameters in the livephotos_photo shortcode in all versions up to, and including, 0.1. This is due to insufficient input sanitization and output escaping on user-supplied… | |
| Aplazada | Media (6.4) | 0.22% | — | Five9 Live ChatAI | 11/11/2025 | 17/6/2026 | The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'toolbar' attribute of the [five9-chat] shortcode in all versions up to, and including, 1.1.2. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.3) | 0.24% | — | Bishopfox SliverAI | 28/10/2025 | 17/6/2026 | Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or… | |
| Aplazada | Media (5.3) | 0.53% | — | Tawk Live ChatAI | 20/10/2025 | 17/6/2026 | Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a malicious PDF with JavaScript payload through the chatbot. The PDF is stored by the application and subsequently displayed without proper… |