Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2769 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 1.2% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload… | |
| Analizada | Crítica (9.8) | 0.42% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 0.76% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 0.67% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. | |
| Aplazada | Media (5.4) | 0.33% | — | Ammarahmad786 Calculate Prices Based ON Distance FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices-based-on-distance-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through <=… | |
| Aplazada | Media (5.1) | 0.32% | — | Vmware Spring Cloud BaseAI | 6/5/2025 | 17/6/2026 | A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file… | |
| Analizada | Alta (8.9) | 1.0% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , if model_name contains the string… | |
| Analizada | Alta (8.9) | 1.0% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function in vr.py. In uvr , a new instance of AudioPre class is… | |
| Analizada | Alta (8.9) | 0.95% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_dir variable takes user input (e.g. a path to a model) and passes it to the change_info function in export.py, which uses it to load the model on that… | |
| Analizada | Alta (8.9) | 0.95% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_a and cpkt_b variables take user input (e.g. a path to a model) and pass it to the merge function in process_ckpt.py, which uses them to load the models… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path0 variable takes user input (e.g. a path to a model) and passes it to the change_info function in process_ckpt.py, which uses it to load the model on… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to the extract_small_model function in process_ckpt.py, which uses it to load the… | |
| Analizada | Alta (8.9) | 0.96% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to unsafe deserialization. The ckpt_path1 variable takes user input (e.g. a path to a model) and passes it to the show_info function in process_ckpt.py, which uses it to load the model on… | |
| Analizada | Alta (8.9) | 0.99% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to code injection. The ckpt_path2 variable takes user input (e.g. a path to a model) and passes it to change_info_ function, which opens and reads the file on the given path (except it… | |
| Analizada | Alta (8.9) | 2.2% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, among others, take user input and pass it to the click_train function, which concatenates them into a command that is run on the server. This… | |
| Analizada | Alta (8.9) | 2.4% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7 and f0method8 take user input and pass it into the extract_f0_feature function, which concatenates them into a command that is run on the… | |
| Analizada | Alta (8.9) | 2.2% | — | Rvc-project Retrieval-based-voice-conversion-webui | 5/5/2025 | 17/6/2026 | Retrieval-based-Voice-Conversion-WebUI is a voice changing framework based on VITS. Versions 2.2.231006 and prior are vulnerable to command injection. The variables exp_dir1, np7, trainset_dir4 and sr2 take user input and pass it to the preprocess_dataset function, which concatenates them into a command that is run on… | |
| Modificada | Media (6.1) | 0.29% | — | Senior-walter Web-based Pharmacy Product Management System | 5/5/2025 | 17/6/2026 | SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field. | |
| Aplazada | Media (5.9) | 0.47% | — | Database ToolsetAI | 3/5/2025 | 17/6/2026 | The Database Toolset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.4 via backup files stored in a publicly accessible location. This makes it possible for unauthenticated attackers to extract sensitive data from database backup files. An index file is… | |
| Aplazada | Alta (8.7) | 0.45% | — | Base-xAI | 30/4/2025 | 17/6/2026 | base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1. | |
| Analizada | Alta (7.6) | 0.48% | — | Couchbase Server | 30/4/2025 | 17/6/2026 | A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow. | |
| Aplazada | Alta (7.1) | 0.15% | — | Yash Binani Time Based GreetingAI | 24/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Yash Binani Time Based Greeting time-based-greeting allows Stored XSS.This issue affects Time Based Greeting: from n/a through <= 2.2.2. | |
| Aplazada | Crítica (9.1) | 1.1% | — | Database ToolsetAI | 24/4/2025 | 17/6/2026 | The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the… | |
| Analizada | Media (4.8) | 0.40% | — | Senior-walter Web-based Pharmacy Product Management System | 20/4/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_name/txtaddress leads to cross site scripting. It is possible to initiate the… |