Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Uipress LiteAI | 21/11/2025 | 7/10/2026 | The UiPress lite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.08. This is due to missing capability checks in the 'uip_process_block_query' AJAX function. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Analizada | Alta (7.3) | 0.36% | — | Lite-xl Lite XL | 20/11/2025 | 17/6/2026 | Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This function was used in project directory launching (core.lua), drag-and-drop file handling (rootview.lua), and the “open in system” command… | |
| Analizada | Alta (7.3) | 0.33% | — | Lite-xl Lite XL | 20/11/2025 | 17/6/2026 | Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.lua file is intended for project-specific configuration but can contain executable Lua logic. This behavior could allow execution of… | |
| Aplazada | Media (5.8) | 0.47% | — | WP Migrate LiteAI | 18/11/2025 | 17/6/2026 | The WP Migrate Lite – WordPress Migration Made Easy plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.7.6 via the wpmdb_flush AJAX action. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the… | |
| Aplazada | Media (4.3) | 0.14% | — | CTL Arcade LiteAI | 11/11/2025 | 7/10/2026 | The CTL Arcade Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on the 'ctl_arcade_lite_page_manage_games' page. This makes it possible for unauthenticated attackers to deactivate and activate arbitrary… | |
| Aplazada | Media (5.5) | 0.25% | — | Wpdreams Ajax Search LiteAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpdreams Ajax Search Lite ajax-search-lite allows Object Injection.This issue affects Ajax Search Lite: from n/a through <= 4.13.3. | |
| Aplazada | Alta (7.2) | 0.51% | — | Dmitry V Barcode Scanner Lite POS TO Manage Products Inventory AND OrdersAI | 6/11/2025 | 7/10/2026 | Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through <= 1.10.4. | |
| Aplazada | Media (6.1) | 0.27% | — | Morehubbub Hubbub LiteAI | 6/11/2025 | 7/10/2026 | The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dpsp_list_attention_search' parameter in all versions up to, and including, 1.36.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (8) | 0.62% | — | Redhat SatelliteAITheforeman ForemanAI | 5/11/2025 | 17/6/2026 | A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting. | |
| Aplazada | Media (6.5) | 0.27% | — | Codebangers ALL IN ONE Time Clock LiteAI | 4/11/2025 | 17/6/2026 | The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization check in all versions up to, and including, 2.0.3. This is due to the plugin exposing admin-level AJAX actions to unauthenticated users via wp_ajax_nopriv_ hooks, while relying only on a nonce check… | |
| Aplazada | Media (5.3) | 0.37% | 💥 PoC | Document Library LiteAI | 1/11/2025 | 17/6/2026 | The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and including, 1.1.6. This is due to the plugin exposing an unauthenticated AJAX action dll_load_posts which returns a JSON table of document data without performing nonce or capability checks. The handler… | |
| Aplazada | Baja (3.5) | 0.35% | 💥 PoC | LitellmAI | 29/10/2025 | 17/6/2026 | LiteLLM Information health API_KEY Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of LiteLLM. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of the API_KEY parameter… | |
| Aplazada | Media (6.1) | 0.38% | — | Litespeedtech Litespeed CacheAI | 29/10/2025 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, and including, 7.5.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Aplazada | Crítica (9.1) | 0.33% | — | Etimetype LiteAI | 27/10/2025 | 17/6/2026 | An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection configurations. | |
| Aplazada | Alta (7.1) | 0.13% | — | Nikanwp WC Reports LiteAI | 27/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NikanWP NikanWP WooCommerce Reporting wc-reports-lite allows Stored XSS.This issue affects NikanWP WooCommerce Reporting: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.20% | — | Nick Diego Blox LiteAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Diego Blox Lite blox-lite allows Stored XSS.This issue affects Blox Lite: from n/a through <= 1.2.8. | |
| Aplazada | Media (4.3) | 0.24% | — | Wplab Wp-lister Lite FOR EbayAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WP Lab WP-Lister Lite for eBay wp-lister-for-ebay allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP-Lister Lite for eBay: from n/a through <= 3.8.3. | |
| Aplazada | Alta (7.3) | 0.18% | — | Langchain Langgraph-checkpoint-sqliteAILangchainAI | 26/10/2025 | 17/6/2026 | A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct… | |
| Aplazada | Alta (7.1) | 0.13% | — | Johnh10 Video Blogster LiteAI | 22/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Stored XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2. | |
| Aplazada | Alta (7.1) | 0.24% | — | Basix Nex-forms LiteAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms LITE nex-forms-lite allows Reflected XSS.This issue affects NEX-Forms LITE: from n/a through < 8.2. | |
| Aplazada | Alta (7.2) | 0.43% | — | Dokan LiteAI | 22/10/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Dokan, Inc. Dokan dokan-lite allows Privilege Escalation.This issue affects Dokan: from n/a through <= 4.1.3. | |
| Aplazada | Alta (7.1) | 0.24% | — | Daman Jeet Finale LiteAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daman Jeet Finale Lite finale-woocommerce-sales-countdown-timer-discount allows Reflected XSS.This issue affects Finale Lite: from n/a through <= 2.20.0. | |
| Aplazada | Alta (8.2) | 0.31% | — | Amenotech Private Limited WpguppyAIAmenotech Private Limited Wpguppy LiteAI | 22/10/2025 | 17/6/2026 | Missing Authorization vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPGuppy: from n/a through <= 1.1.4. | |
| Aplazada | Media (4.3) | 0.19% | — | Codebangers ALL IN ONE Time Clock LiteAI | 22/10/2025 | 17/6/2026 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0 via the 'aio_time_clock_lite_js' AJAX action due to missing validation on a user controlled key. This makes it possible for… | |
| Aplazada | Media (4.4) | 0.30% | 💥 PoC | Related Posts LiteAI | 18/10/2025 | 17/6/2026 | The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… |