Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.98% | 💥 Exploit | Vitejs ViteVoidzero Vite+ | 7/4/2026 | 24/7/2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow… | |
| Modificada | Alta (8.2) | 1.5% | 💥 Exploit | Vitejs ViteVoidzero Vite+ | 7/4/2026 | 4/8/2026 | Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This… | |
| Modificada | Alta (8.2) | 2.6% | 💥 Exploit | Vitejs ViteVoidzero Vite+ | 7/4/2026 | 25/8/2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to… | |
| Analizada | Crítica (9.3) | 0.60% | — | Linuxfoundation Vitess | 26/2/2026 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that files in the manifest — which may be files that they have also added to the manifest… | |
| Analizada | Alta (8.4) | 0.69% | — | Linuxfoundation Vitess | 26/2/2026 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest files so that arbitrary code is later executed when that backup is restored. This can be used to… | |
| Analizada | Media (5.3) | 0.23% | — | Metadrop Group Invite | 4/2/2026 | 17/6/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Group invite allows Forceful Browsing.This issue affects Group invite: from 0.0.0 before 2.3.9, from 3.0.0 before 3.0.4, from 4.0.0 before 4.0.4. | |
| Aplazada | Alta (7.5) | 0.51% | — | Vitejs Plugin RSAI | 16/12/2025 | 17/6/2026 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Prior to version 0.5.8, the `/__vite_rsc_findSourceMapURL` endpoint in `@vitejs/plugin-rsc` allows unauthenticated arbitrary file read during development mode. An attacker can read any file accessible to the Node.js process by sending a crafted… | |
| Aplazada | Crítica (9.8) | 0.81% | — | Vitejs Plugin RSAI | 9/12/2025 | 17/6/2026 | @vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to arbitrary remote code execution on the development server through unsafe dynamic imports in server function APIs (loadServerAction, decodeReply, decodeAction) when integrated into RSC applications that… | |
| Aplazada | Media (4.3) | 0.24% | — | Gravitec.net WEB Push NotificationsAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Gravitec.net - Web Push Notifications Gravitec.net – Web Push Notifications gravitec-net-web-push-notifications allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gravitec.net – Web Push Notifications: from n/a through <= 2.9.17. | |
| Aplazada | Media (5) | 0.33% | — | KivitendoAI | 28/11/2025 | 17/6/2026 | Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files from the server's filesystem. | |
| Aplazada | Alta (8.8) | 0.69% | 💥 PoC | ViteposAI | 21/11/2025 | 17/6/2026 | The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the insert_media_attachment() function in all versions up to, and including, 3.3.0. This is due to the save_update_category_img() function accepting user-supplied file… | |
| Aplazada | Media (6) | 1.1% | 💥 Exploit | Vitejs ViteAI | 20/10/2025 | 17/6/2026 | Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5.3 to before 5.0.0, 5.2.6 to before 5.4.21, 6.0.0 to before 6.4.1, 7.0.0 to before 7.0.8, and 7.1.0 to before 7.1.11, files denied by server.fs.deny were sent if the URL ended with \ when the dev… | |
| Aplazada | Baja (2.9) | 0.38% | — | Cloudflare Vite PluginAI | 19/9/2025 | 17/6/2026 | The Cloudflare Vite plugin enables a full-featured integration between Vite and the Workers runtime. When utilising the Cloudflare Vite plugin in its default configuration, all files are exposed by the local dev server, including files in the root directory that contain secret information such as .env and .dev.vars.… | |
| Aplazada | Alta (8.8) | 0.41% | — | Error-exAIBabelAINext.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | error-ex allows error subclassing and stack customization. On 8 September 2025, an npm publishing account for error-ex was taken over after a phishing attack. Version 1.3.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency… | |
| Aplazada | Alta (8.8) | 0.41% | — | Simple-swizzleAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 17/6/2026 | simple-swizzle swizzles function arguments. On 8 September 2025, the npm publishing account for simple-swizzle was taken over after a phishing attack. Version 0.2.3 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions… | |
| Aplazada | Alta (8.8) | 0.41% | — | BacklashAINPMAIBabelAIVercel Next.jsAI+2 | 15/9/2025 | 17/6/2026 | backlash parses collected strings with escapes. On 8 September 2025, the npm publishing account for backslash was taken over after a phishing attack. Version 0.2.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to… | |
| Aplazada | Alta (8.8) | 0.55% | — | Color-nameAIBabelAIVercel Next.jsAIRollupjs RollupAI+1 | 15/9/2025 | 30/9/2026 | color-name is a JSON with CSS color names. On 8 September 2025, an npm publishing account for color-name was taken over after a phishing attack. Version 2.0.1 was published, functionally identical to the previous patch version, but with a malware payload added attempting to redirect cryptocurrency transactions to the… | |
| Analizada | Baja (2.3) | 1.2% | 💥 Exploit | Vitejs Vite | 8/9/2025 | 17/6/2026 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the public directory were served bypassing the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or `server.host` config… | |
| Analizada | Baja (2.3) | 0.61% | — | Vitejs Vite | 8/9/2025 | 30/9/2026 | Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server to the network (using --host or server.host config option) and use `appType:… | |
| Aplazada | Media (5.3) | 0.22% | — | Devitems Support GenixAI | 3/9/2025 | 17/6/2026 | Missing Authorization vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.23. | |
| Aplazada | Media (6) | 0.42% | — | Vite-plugin-static-copyAIRollup-plugin-copyAI | 21/8/2025 | 17/6/2026 | vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible with a crafted request. The vulnerability is fixed in 2.3.2 and 3.1.2. | |
| Aplazada | Media (5.9) | 0.27% | — | Sarveshmrao WP Discord InviteAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarvesh M Rao WP Discord Invite wp-discord-invite allows Stored XSS.This issue affects WP Discord Invite: from n/a through <= 2.5.3. | |
| Analizada | Media (6) | 1.2% | 💥 Exploit | Vitejs Vite | 1/5/2025 | 17/6/2026 | Vite is a frontend tooling framework for javascript. Prior to versions 6.3.4, 6.2.7, 6.1.6, 5.4.19, and 4.5.14, the contents of files in the project root that are denied by a file matching pattern can be returned to the browser. Only apps explicitly exposing the Vite dev server to the network (using --host or… | |
| Aplazada | Alta (7.2) | 0.48% | — | Appsbd Vitepos LiteAI | 17/4/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3.1.7. | |
| Aplazada | Media (6) | 1.7% | 💥 Exploit | Vitejs ViteAI | 10/4/2025 | 17/6/2026 | Vite is a frontend tooling framework for javascript. Prior to 6.2.6, 6.1.5, 6.0.15, 5.4.18, and 4.5.13, the contents of arbitrary files can be returned to the browser if the dev server is running on Node or Bun. HTTP 1.1 spec (RFC 9112) does not allow # in request-target. Although an attacker can send such a request.… |