Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.70% | — | Lavalite | 1/8/2023 | 17/6/2026 | LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | |
| Modificada | Media (5.4) | 0.38% | — | Lavalite | 18/5/2023 | 17/6/2026 | LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 0.87% | — | Lavalite | 12/5/2023 | 17/6/2026 | LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning. | |
| Modificada | Media (6.1) | 0.59% | — | Lavalite | 12/5/2023 | 9/7/2026 | LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. | |
| Modificada | Crítica (9.8) | 2.0% | — | Linaro Lava | 18/11/2022 | 17/6/2026 | In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution… | |
| Modificada | Media (6.5) | 1.0% | — | Linaro LavaDebian Linux | 18/11/2022 | 17/6/2026 | In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service. | |
| Modificada | Alta (7.5) | 1.0% | — | Lavalite | 18/10/2022 | 17/6/2026 | In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. | |
| Modificada | Alta (8.8) | 1.4% | — | Linaro LavaDebian Linux | 13/10/2022 | 17/6/2026 | In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server. | |
| Modificada | Media (4.8) | 0.62% | — | Lavalite | 26/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,". | |
| Modificada | Media (4.8) | 0.59% | — | Lavalite | 7/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature. | |
| Modificada | Media (5.4) | 0.51% | — | Lavalite | 2/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter. | |
| Modificada | Media (5.4) | 0.50% | — | Lavalite | 2/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter. | |
| Modificada | Media (5.4) | 0.51% | — | Lavalite | 2/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter. | |
| Modificada | Media (5.4) | 0.52% | — | Lavalite | 14/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field. | |
| Modificada | Media (5.5) | 0.25% | — | Lavamobiles Z60s Firmware | 14/11/2019 | 17/6/2026 | The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an… | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Iris 88 Lite Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Z61 Turbo Firmware | 14/11/2019 | 17/6/2026 | The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property… | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Z92 Firmware | 14/11/2019 | 17/6/2026 | The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported… | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Iris 88 Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property… | |
| Modificada | Media (5.5) | 0.29% | — | Lavamobiles Flair Z1 Firmware | 14/11/2019 | 17/6/2026 | The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Z60s Firmware | 14/11/2019 | 17/6/2026 | The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Iris 88 Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Z81 Firmware | 14/11/2019 | 17/6/2026 | The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically disable and enable… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Z61 Firmware | 14/11/2019 | 17/6/2026 | The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Z92 Firmware | 14/11/2019 | 17/6/2026 | The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable… |