Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1807 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.27%—Strangerstudios Memberlite ShortcodesAI17/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1.
AplazadaAlta (7.5)0.48%—LitestarAI6/10/202517/6/2026
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers. Litestar's RateLimitMiddleware uses `cache_key_from_request()` to…
AplazadaMedia (6.4)0.30%—Ultra Addons LiteAI3/10/202517/6/2026
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Animated Text' field of the Typeout Widget in version 1.1.9 and below due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaAlta (8.6)0.33%—CTL Behance Importer LiteAI2/10/202517/6/2026
The CTL Behance Importer Lite WordPress plugin through 1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
AplazadaBaja (2.1)0.41%—VETAISqlite3AI29/9/202517/6/2026
vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP Host and Origin header validation. Data from the vet scan sqlite3 database may be exposed to remote attackers when vet is used as an MCP server in SSE mode with default…
AplazadaAlta (7.5)0.39%—Maciej BIS Permalink Manager LiteAI26/9/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager allows Retrieve Embedded Sensitive Data.This issue affects Permalink Manager Lite: from n/a through <= 2.5.1.3.
AplazadaMedia (5)0.21%—Satellite Management ControllerAI23/9/202517/6/2026
Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.
AplazadaMedia (6.5)0.20%—Russelljamieson Genesis Club LiteAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Genesis Club Lite genesis-club-lite allows Stored XSS.This issue affects Genesis Club Lite: from n/a through <= 1.17.
AplazadaMedia (4.3)0.29%—Nerdpress Hubbub LiteAI22/9/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NerdPress Hubbub Lite social-pug allows Retrieve Embedded Sensitive Data.This issue affects Hubbub Lite: from n/a through <= 1.35.2.
AplazadaMedia (6.4)0.28%—Strangerstudios Memberlite ShortcodesAI17/9/202525/9/2026
The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'row' shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.27%💥 PoCAvtech Eagleeyes(lite)15/9/202517/6/2026
An issue was discovered in the method push.lite.avtech.com.MySSLSocketFactoryNew.checkServerTrusted in AVTECH EagleEyes 2.0.0. The custom X509TrustManager used in checkServerTrusted only checks the certificate's expiration date, skipping proper TLS chain validation.
AplazadaAlta (8.8)0.27%💥 PoCAvtech Eagleeyes LiteAI15/9/202517/6/2026
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS
AnalizadaCrítica (9.8)0.66%💥 PoCAvtech Eagleeyes(lite)15/9/202517/6/2026
An issue was discovered in the methods push.lite.avtech.com.AvtechLib.GetHttpsResponse and push.lite.avtech.com.Push_HttpService.getNewHttpClient in AVTECH EagleEyes 2.0.0. The methods set ALLOW_ALL_HOSTNAME_VERIFIER, bypassing domain validation.
AnalizadaBaja (2.1)0.35%—Linlinjava Litemall12/9/202517/6/2026
A weakness has been identified in linlinjava litemall up to 1.8.0. This affects the function WxAftersaleController of the file /wx/aftersale/cancel. Executing manipulation of the argument ID can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and…
AplazadaMedia (6.4)0.26%—Litespeed Technologies Litespeed CacheAI9/9/202517/6/2026
Server-Side Request Forgery (SSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache.This issue affects LiteSpeed Cache: from n/a through <= 7.0.1.
AplazadaMedia (6.9)0.35%—Sqlite Fts5AI8/9/202517/6/2026
An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.
AplazadaMedia (4.3)0.13%—Related Posts LiteAI30/8/202517/6/2026
The Related Posts Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to modify plugin settings via a forged…
AplazadaMedia (4.7)0.35%—Hikvision Hikcentral Master LiteAI29/8/202517/6/2026
There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.
AplazadaAlta (8.1)0.54%—Unfoldwp Magazine EliteAI28/8/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magazine Elite magazine-elite allows PHP Local File Inclusion.This issue affects Magazine Elite: from n/a through <= 1.2.4.
AplazadaMedia (5.3)0.30%—Ajax Search LiteAI28/8/202517/6/2026
The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in its AJAX search handler in all versions up to, and including, 4.13.1. This makes it possible for unauthenticated attackers to issue repeated AJAX requests to leak the content of any protected post in…
AnalizadaAlta (8.8)0.54%—Elite Project Elite22/8/202517/6/2026
OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
AplazadaAlta (8.1)0.26%—UI Unifi Connect Display CastAIUI Unifi Connect Display Cast PROAIUI Unifi Connect Display Cast LiteAI21/8/202517/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported changes to the system. Affected Products: UniFi Connect Display Cast (Version 1.10.3 and earlier) UniFi Connect Display Cast Pro (Version 1.0.89 and earlier) UniFi Connect…
AplazadaMedia (4.9)0.25%—UI Unifi Connect EV Station PROAIUI Unifi Connect DisplayAIUI Unifi Connect Display CastAIUI Unifi Connect Display Cast PROAI+121/8/202517/6/2026
An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect devices to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and earlier) UniFi Connect Display (Version 1.9.324 and…
AplazadaCrítica (9.8)1.2%—UI Unifi Connect EV Station LiteAI21/8/202517/6/2026
Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite. Affected Products: UniFi Connect EV Station Lite (Version 1.5.1 and earlier) Mitigation: Update UniFi Connect EV Station Lite…
AplazadaMedia (5.1)0.32%—Influx Initiative OnboardliteAI20/8/202517/6/2026
OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, credential theft,…
Orbitaley — Vulnerabilidades