Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.45% | — | Beastthemes Clockinator LiteAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in BeastThemes Clockinator Lite clockify-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clockinator Lite: from n/a through <= 1.0.9. | |
| Aplazada | Media (6.5) | 0.36% | — | Otwthemes Post Custom Templates LiteAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Post Custom Templates Lite post-custom-templates-lite allows Stored XSS.This issue affects Post Custom Templates Lite: from n/a through <= 1.14. | |
| Aplazada | Media (6.5) | 0.36% | — | Wpelite HMH Footer Builder FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPelite HMH Footer Builder For Elementor hmh-footer-builder-for-elementor allows Stored XSS.This issue affects HMH Footer Builder For Elementor: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.83% | — | WP Shuffle Subscribe TO Download LiteAI | 1/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite subscribe-to-download-lite allows PHP Local File Inclusion.This issue affects Subscribe to Download Lite: from n/a through <= 1.2.9. | |
| Aplazada | Alta (8.8) | 0.49% | — | Appsbd Vitepos LiteAI | 1/4/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3.1.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Crazycric Ultimate Live Cricket LiteAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in crazycric Ultimate Live Cricket WordPress Lite ultimate-live-cricket-lite allows Stored XSS.This issue affects Ultimate Live Cricket WordPress Lite: from n/a through <= 1.4.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Yudleethemes Whitish LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whitish Lite allows Stored XSS.This issue affects Whitish Lite: from n/a through 2.1.13. | |
| Aplazada | Media (5.3) | 0.51% | — | VegaAIVega-functionsAIVega-liteAI | 27/3/2025 | 17/6/2026 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. In Vega prior to version 5.32.0, corresponding to vega-functions prior to version 5.17.0, users running Vega/Vega-lite JSON definitions could run unexpected JavaScript code when drawing graphs,… | |
| Aplazada | Media (6.5) | 0.22% | — | Victortihai Morningtime LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in victortihai MorningTime Lite morningtime-lite allows Stored XSS.This issue affects MorningTime Lite: from n/a through <= 1.3.2. | |
| Aplazada | Media (4.3) | 0.21% | — | Wp3dprinting 3dprint LiteAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fuzzoid 3DPrint Lite 3dprint-lite allows Cross Site Request Forgery.This issue affects 3DPrint Lite: from n/a through <= 2.1.3.5. | |
| Aplazada | Alta (7.5) | 1.0% | — | Wpshuffle Subscribe TO Download LiteAI | 27/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Download Lite subscribe-to-download-lite allows PHP Local File Inclusion.This issue affects Subscribe to Download Lite: from n/a through <= 1.2.9. | |
| Aplazada | Alta (8.5) | 0.49% | — | Amentotech Private Limited Wpguppy LiteAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AmentoTech Private Limited WPGuppy wpguppy-lite allows SQL Injection.This issue affects WPGuppy: from n/a through <= 1.1.3. | |
| Aplazada | Alta (7.1) | 0.19% | — | Alexvtn WIP Woocarousel LiteAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alexvtn WIP WooCarousel Lite wip-woocarousel-lite allows Stored XSS.This issue affects WIP WooCarousel Lite: from n/a through <= 1.1.7. | |
| Aplazada | Alta (8.1) | 1.0% | — | Alex Furr Linkedin-liteAI | 26/3/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Alex Furr LinkedIn Lite linkedin-lite allows PHP Local File Inclusion.This issue affects LinkedIn Lite: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Ghoszylab Gallery FOR Social Photo Feed Instagram LiteAI | 25/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Gallery for Social Photo feed-instagram-lite allows Stored XSS.This issue affects Gallery for Social Photo: from n/a through <= 1.0.0.35. | |
| Aplazada | Alta (8.1) | 0.34% | — | LitellmAI | 20/3/2025 | 17/6/2026 | An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be used to access all the admin functionality of the application, including… | |
| Analizada | Alta (7.5) | 0.56% | — | Litellm | 20/3/2025 | 17/6/2026 | In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing… | |
| Analizada | Alta (7.5) | 0.75% | — | Litellm | 20/3/2025 | 17/6/2026 | In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret… | |
| Modificada | Alta (7.5) | 0.84% | — | Litellm | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and… | |
| Modificada | Alta (8.8) | 1.7% | — | Litellm | 20/3/2025 | 17/6/2026 | BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules' configuration, where a callback function can be added. The provided value is split at the final '.' mark, with the last part considered the function name and the… | |
| Aplazada | Alta (7.5) | 0.56% | — | LitellmAI | 20/3/2025 | 17/6/2026 | A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server. | |
| Aplazada | Baja (3.3) | 0.15% | — | Redhat SatelliteAITheforeman ForemanAI | 15/3/2025 | 17/6/2026 | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. | |
| Analizada | Media (4.3) | 0.33% | — | Jozoor Shortcode Cleaner Lite | 8/3/2025 | 17/6/2026 | The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and including, 1.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export arbitrary… | |
| Aplazada | Media (6.4) | 0.24% | — | Backdrop CMSAIBootstrap LiteAI | 7/3/2025 | 17/6/2026 | An XSS issue was discovered in the Bootstrap Lite theme before 1.x-1.4.5 for Backdrop CMS. It doesn't sufficiently sanitize certain class names. | |
| Aplazada | Media (6.4) | 0.24% | — | Backdrop CMSAIBootstrap 5 LiteAI | 7/3/2025 | 17/6/2026 | An XSS issue was discovered in the Bootstrap 5 Lite theme before 1.x-1.0.3 for Backdrop CMS. It doesn't sufficiently sanitize certain class names. |