Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Sa9000p FirmwareQualcomm Sar2130p FirmwareQualcomm Snapdragon 8 Gen1 5G FirmwareQualcomm Sd662 Firmware+149 | 2/2/2026 | 17/6/2026 | Memory Corruption while deallocating graphics processing unit memory buffers due to improper handling of memory pointers. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Wsa8845h FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Flight RB5 5G Firmware+143 | 2/2/2026 | 17/6/2026 | Memory Corruption when initiating GPU memory mapping using scatter-gather lists due to unchecked IOMMU mapping errors. | |
| Aplazada | Alta (8.4) | 0.48% | — | Bearshare LiteAI | 29/1/2026 | 17/6/2026 | BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content into the search keywords field. | |
| Aplazada | Media (4.6) | 0.42% | — | Mocha Telnet LiteAI | 29/1/2026 | 17/6/2026 | Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the user configuration input. Attackers can overwrite the 'User' field with 350 bytes of repeated characters to trigger an application crash and prevent normal functionality. | |
| Aplazada | Media (6.7) | 0.15% | — | Visualfc LiteideAI | 27/1/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in visualfc liteide (liteidex/src/3rdparty/libvterm/src modules). This vulnerability is associated with program files screen.C, state.C, vterm.C. This issue affects liteide: before x38.4. | |
| Aplazada | Media (6.8) | 0.34% | — | Recipe Card Blocks LiteAI | 26/1/2026 | 17/6/2026 | The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks. | |
| Analizada | Media (5.1) | 0.23% | — | Lavalite | 23/1/2026 | 14/7/2026 | LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper output encoding in… | |
| Aplazada | Alta (8.6) | 1.6% | — | Litespeed WEB Server EnterpriseAI | 23/1/2026 | 17/6/2026 | LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash… | |
| Aplazada | Media (4.3) | 0.22% | — | Syedbalkhi Sugar Calendar LiteAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Syed Balkhi Sugar Calendar (Lite) sugar-calendar-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sugar Calendar (Lite): from n/a through <= 3.9.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Damian Wp-popups-liteAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Damian WP Popups wp-popups-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Popups: from n/a through <= 2.2.0.5. | |
| Aplazada | Media (5.3) | 0.35% | — | Xlplugins Nextmove LiteAI | 23/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in XLPlugins NextMove Lite woo-thank-you-page-nextmove-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects NextMove Lite: from n/a through <= 2.23.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Pixelite WP FullcalendarAI | 23/1/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Retrieve Embedded Sensitive Data.This issue affects WP FullCalendar: from n/a through <= 1.6. | |
| Aplazada | Crítica (9.3) | 0.43% | — | WOO MailerliteAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite – WooCommerce integration: from n/a through <= 3.1.2. | |
| Aplazada | Media (5.1) | 0.28% | — | Litespeedtech OpenlitespeedAI | 21/1/2026 | 17/6/2026 | Openlitespeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows administrators to inject malicious scripts. Attackers can craft a payload in the Notes field during listener configuration that will execute when an administrator clicks on the Default Icon. | |
| Aplazada | Alta (7.3) | 0.27% | — | OnboardliteAI | 19/1/2026 | 17/6/2026 | OnboardLite is a comprehensive membership lifecycle platform built for student organizations at the University of Central Florida. Versions of the software prior to commit 1d32081a66f21bcf41df1ecb672490b13f6e429f have a stored cross-site scripting vulnerability that can be rendered to an admin when they attempt to… | |
| Aplazada | Media (6.5) | 0.34% | — | Mailerlite Woocommerce IntegrationAI | 16/1/2026 | 17/6/2026 | The MailerLite - WooCommerce integration plugin for WordPress is vulnerable to unauthorized data modification and deletion in all versions up to, and including, 3.1.3. This is due to missing capability checks on the resetIntegration() function. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.8) | 0.57% | — | Supreme Modules LiteAI | 15/1/2026 | 17/6/2026 | The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it… | |
| Aplazada | Media (4.4) | 0.22% | — | Real Post Slider LiteAI | 14/1/2026 | 17/6/2026 | The Real Post Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject… | |
| Aplazada | Media (4.3) | 0.18% | — | Themehunk Oneline LiteAI | 7/1/2026 | 7/10/2026 | Missing Authorization vulnerability in themehunk Oneline Lite oneline-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Oneline Lite: from n/a through <= 6.6. | |
| Analizada | Media (6.5) | 0.15% | — | UI Unifi Connect EV Station Lite Firmware | 5/1/2026 | 17/6/2026 | An Improper Access Control could allow a malicious actor in Wi-Fi range to the EV Station Lite (v1.5.2 and earlier) to use WiFi AutoLink feature on a device that was only adopted via Ethernet. | |
| Aplazada | Media (6.5) | 0.15% | — | Posimyth THE Plus Addons FOR Elementor Page Builder LiteAI | 5/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite allows DOM-Based XSS.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through 5.3.3. | |
| Modificada | Alta (7.5) | 0.31% | — | Wpwebelite Follow MY Blog Post | 5/1/2026 | 7/10/2026 | Missing Authorization vulnerability in wpweb Follow My Blog Post follow-my-blog-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Follow My Blog Post: from n/a through <= 2.4.0. | |
| Aplazada | Media (4.3) | 0.23% | — | Strategy11 Tasty Recipes LiteAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite tasty-recipes-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.18% | — | Strategy11 Tasty Recipes LiteAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Strategy11 Team Tasty Recipes Lite tasty-recipes-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tasty Recipes Lite: from n/a through <= 1.1.5. | |
| Aplazada | Media (5.3) | 0.21% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in tychesoftwares Product Delivery Date for WooCommerce – Lite product-delivery-date-for-woocommerce-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through <= 3.2.0. |