Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.24% | — | Creativemedia Elite Video PlayerAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Reflected XSS.This issue affects Elite Video Player: from n/a through <= 10.0.5. | |
| Aplazada | Media (6.5) | 0.36% | — | Webba Booking LiteAI | 20/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 5.1.20. | |
| Aplazada | Media (4.3) | 0.41% | 💥 PoC | Eventontemplates Eventon LiteAI | 15/8/2025 | 17/6/2026 | The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.6 via the add_single_eventon and add_eventon shortcodes due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from… | |
| Analizada | Baja (2.1) | 0.33% | — | Linlinjava Litemall | 15/8/2025 | 17/6/2026 | A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_freight_min leads to business logic errors. The attack can be… | |
| Aplazada | Media (5.9) | 0.18% | — | Webba Booking LiteAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Stored XSS.This issue affects Webba Booking: from n/a through <= 6.0.5. | |
| Analizada | Baja (2.9) | 0.53% | — | Linlinjava Litemall | 14/8/2025 | 17/6/2026 | A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Token Handler. The manipulation of the argument SECRET with the input… | |
| Analizada | Baja (2.1) | 0.37% | — | Linlinjava Litemall | 14/8/2025 | 17/6/2026 | A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the argument File leads to unrestricted upload. The… | |
| Aplazada | Alta (7.1) | 0.23% | — | Johnh10 Video Blogster LiteAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in johnh10 Video Blogster Lite video-blogster-lite allows Reflected XSS.This issue affects Video Blogster Lite: from n/a through <= 1.2. | |
| Analizada | Baja (2.1) | 0.25% | — | Linlinjava Litemall | 9/8/2025 | 17/6/2026 | A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upload. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Baja (2.1) | 0.51% | — | Linlinjava Litemall | 9/8/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete of the file /admin/storage/delete of the component File Handler. The manipulation of the argument key leads to path traversal. The attack may be launched remotely. The… | |
| Aplazada | Alta (8.1) | 1.0% | — | Emarketdesign EMD Form Builder LiteAI | 6/8/2025 | 17/6/2026 | Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible… | |
| Analizada | Alta (8.8) | 0.68% | — | Vjinfotech WP Import Export Lite | 5/8/2025 | 17/6/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_import' function in all versions up to, and including, 3.9.28. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions… | |
| Analizada | Alta (8.8) | 0.71% | — | Vjinfotech WP Import Export Lite | 5/8/2025 | 17/6/2026 | The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_upload_data' function in all versions up to, and including, 3.9.29. This makes it possible for authenticated attackers, with Subscriber-level access and above, and permissions… | |
| Aplazada | Media (6.4) | 0.23% | — | Magic Edge LiteAI | 2/8/2025 | 17/6/2026 | The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.1) | 0.21% | — | Codebangers ALL IN ONE Time Clock LiteAI | 2/8/2025 | 17/6/2026 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Crítica (9.3) | 1.6% | 💥 Exploit | Havalite CMSAI | 1/8/2025 | 16/6/2026 | An unauthenticated arbitrary file upload vulnerability exists in Havalite CMS version 1.1.7 (and possibly earlier) in the upload.php script. The application fails to enforce proper file extension validation and authentication checks, allowing remote attackers to upload malicious PHP files via a crafted… | |
| Analizada | Alta (7.5) | 0.80% | 💥 PoC | Litespeedtech Litespeed WEB ADCLitespeedtech Litespeed WEB ServerLitespeedtech LsquicLitespeedtech Openlitespeed | 1/8/2025 | 17/6/2026 | LiteSpeed QUIC (LSQUIC) Library before 4.3.1 has an lsquic_engine_packet_in memory leak. | |
| Aplazada | Alta (8.6) | 1.7% | 💥 Exploit | Mplayer LiteAI | 31/7/2025 | 16/6/2026 | A stack-based buffer overflow vulnerability exists in MPlayer Lite r33064 due to improper bounds checking when handling M3U playlist files containing long http:// URL entries. An attacker can craft a malicious .m3u file with a specially formatted URL that triggers a stack overflow when processed by the player,… | |
| Analizada | Media (6.9) | 0.24% | — | Sqlite | 29/7/2025 | 17/6/2026 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of… | |
| Aplazada | Media (4.3) | 0.19% | — | Bonanza Woocommerce Free Gifts LiteAI | 29/7/2025 | 17/6/2026 | The Bonanza – WooCommerce Free Gifts Lite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the xlo_optin_call() function in all versions up to, and including, 1.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Media (6.4) | 0.29% | — | Wonderplugin Wonder Slider LiteAI | 26/7/2025 | 17/6/2026 | The Wonder Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image title and description DOM in all versions up to, and including, 14.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Alta (8.7) | 0.39% | — | Liteon Ic48aAILiteon Ic80aAI | 16/7/2025 | 17/6/2026 | LITEON IC48A firmware versions prior to 01.00.19r and LITEON IC80A firmware versions prior to 01.01.12e store FTP-server-access-credentials in cleartext in their system logs. | |
| Aplazada | Media (4.3) | 0.14% | — | Webba Booking LiteAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Cross Site Request Forgery.This issue affects Webba Booking: from n/a through <= 5.1.20. | |
| Analizada | Alta (7.2) | 71% | 💥 Exploit | SqliteApple IpadosApple Iphone OSApple Macos+5 | 15/7/2025 | 26/6/2026 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. | |
| Analizada | Crítica (9.8) | 0.38% | — | Webnus Modern Events Calendar Lite | 12/7/2025 | 17/6/2026 | The Modern Events Calendar Lite plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'wp_ajax_mec_load_single_page' AJAX action in all versions up to, and including, 6.3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… |