Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.8) | 0.42% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 12/11/2024 | 17/6/2026 | Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway if the appliance must be configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) with KCDAccount configuration for Kerberos SSO to access backend resources OR the appliance must be configured as an Auth Server (AAA… | |
| Analizada | Alta (8.4) | 0.56% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 12/11/2024 | 17/6/2026 | Memory safety vulnerability leading to memory corruption and Denial of Service in NetScaler ADC and Gateway if the appliance must be configured as a Gateway (VPN Vserver) with RDP Feature enabled OR the appliance must be configured as a Gateway (VPN Vserver) and RDP Proxy Server Profile is created and set to Gateway… | |
| Aplazada | Alta (7.1) | 0.27% | — | Firework Shoppable Live VideoAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefan Backor Firework Shoppable Live Video firework-videos allows Reflected XSS.This issue affects Firework Shoppable Live Video: from n/a through <= 6.3. | |
| Aplazada | Media (5.3) | 0.52% | — | Tychesoftwares Product Delivery Date FOR Woocommerce LiteAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Tyche Softwares Product Delivery Date for WooCommerce – Lite allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Delivery Date for WooCommerce – Lite: from n/a through 2.7.2. | |
| Modificada | Crítica (9.8) | 0.53% | — | Buynowdepot Advanced Online Ordering AND Delivery Platform | 28/10/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wdesco Advanced Online Ordering and Delivery Platform advanced-online-ordering-and-delivery-platform allows PHP Local File Inclusion.This issue affects Advanced Online Ordering and Delivery… | |
| Modificada | Crítica (9.8) | 0.77% | — | Olivegroup Olivevle | 25/10/2024 | 17/6/2026 | An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function. | |
| Aplazada | Alta (7.5) | 0.45% | — | Videowhisper Contact FormsAIVideowhisper Live SupportAIVideowhisper CRMAIVideowhisper Video MessagesAI+1 | 17/10/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in videowhisper Contact Forms, Live Support, CRM, Video Messages live-support-tickets allows Retrieve Embedded Sensitive Data.This issue affects Contact Forms, Live Support, CRM, Video Messages: from n/a through <= 1.10.2. | |
| Analizada | Alta (7.7) | 0.85% | 💥 PoC | Laravel Livewire | 8/10/2024 | 17/6/2026 | Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file extension of an uploaded file is guessed based on the MIME type. As a result, the actual file extension from the file name is not validated. An… | |
| Analizada | Media (6.1) | 0.39% | — | Tychesoftwares Product Delivery Date FOR Woocommerce | 4/10/2024 | 17/6/2026 | The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Aplazada | Media (6.4) | 0.34% | — | Rumbletalk Live Group ChatAI | 1/10/2024 | 17/6/2026 | The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rumbletalk-admin-button' shortcode in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.35% | — | Livemeshelementor Addons FOR Elementor | 25/9/2024 | 17/6/2026 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Modificada | Media (5.4) | 0.24% | — | Livemeshelementor Addons FOR Elementor | 25/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Cross-Site Scripting (XSS).This issue affects Livemesh Addons for Elementor: from n/a through <= 8.5. | |
| Aplazada | Media (5.3) | 0.42% | — | Relevanssi Live Ajax SearchAI | 28/8/2024 | 17/6/2026 | The Relevanssi Live Ajax Search plugin for WordPress is vulnerable to argument injection in all versions up to, and including, 2.4. This is due to insufficient validation of input supplied via POST data in the 'search' function. This makes it possible for unauthenticated attackers to inject arbitrary arguments into a… | |
| Aplazada | Media (6.5) | 0.26% | — | Livemesh Addons FOR Wpbakery Page BuilderAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for WPBakery Page Builder addons-for-visual-composer allows Stored XSS.This issue affects Livemesh Addons for WPBakery Page Builder: from n/a through 3.9. | |
| Aplazada | Media (6.4) | 0.34% | — | Sheet TO Table Live Sync FOR Google SheetAI | 14/8/2024 | 17/6/2026 | The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.39% | — | Olivethemes Olive ONE Click Demo Import | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Olive Themes Olive One Click Demo Import allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Olive One Click Demo Import: from n/a through 1.1.2. | |
| Analizada | Alta (8.8) | 0.33% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lead to an attacker tricking the administrator into deleting valid member data via a crafted HTML page, as demonstrated by a Delete Member action at the /delete_members.php. | |
| Analizada | Alta (7.6) | 1.1% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter. | |
| Analizada | Crítica (9.8) | 1.0% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lopalopa Live Membership System | 12/8/2024 | 17/6/2026 | An Unrestricted file upload vulnerability was found in "/Membership/edit_member.php" of Kashipara Live Membership System v1.0, which allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (6.9) | 0.71% | — | Rainniar Bike Delivery System | 6/8/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The manipulation of the argument name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (4.8) | 0.26% | — | Livemesh Beaver Builder Addons | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Beaver Builder allows Stored XSS.This issue affects Livemesh Addons for Beaver Builder: from n/a through 3.6.1. | |
| Aplazada | Alta (7.2) | 0.70% | — | Bishopfox SliverAI | 18/7/2024 | 17/6/2026 | Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver version 1.6.0 (prerelease) is vulnerable to RCE on the teamserver by a low-privileged "operator" user. The RCE is as the system root user. The exploit is… | |
| Aplazada | Crítica (9.8) | 0.62% | — | KeepalivedAI | 18/7/2024 | 17/6/2026 | In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty ipset name must be configured by the user. | |
| Aplazada | Media (6.5) | 0.52% | — | LivechatAI | 12/7/2024 | 17/6/2026 | Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory. |