Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.25%—Lavamobiles Iris 88 Firmware14/11/201917/6/2026
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically…
ModificadaBaja (3.3)0.25%—Lavamobiles Flair Z1 Firmware14/11/201917/6/2026
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable…
ModificadaBaja (3.3)0.25%—Lavamobiles Z61 Firmware14/11/201917/6/2026
The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and…
ModificadaMedia (6.1)0.87%—Lavalite13/11/201917/6/2026
XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field.
ModificadaMedia (5.4)0.60%—Lavalite10/10/201917/6/2026
LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
ModificadaMedia (5.4)0.67%—Lavalite5/9/201817/6/2026
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
ModificadaAlta (8.8)2.5%—Linaro LavaDebian Linux19/6/201817/6/2026
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur.
ModificadaMedia (6.5)1.5%—Linaro LavaDebian Linux19/6/201817/6/2026
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml.
ModificadaMedia (6.5)0.89%—Linaro Lava19/6/201817/6/2026
An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml.
ModificadaMedia (5.4)0.73%—Lavalite3/1/201817/6/2026
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
ModificadaCrítica (9.8)2.6%—Lavalink Ether-serial Link Firmware11/10/201717/6/2026
An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by…
ModificadaMedia (5.4)0.27%—Teamlava Fashion Story\19/10/201417/6/2026
The Fashion Story: Neon 90's (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)71%💥 ExploitLavague11/5/200716/6/2026
PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter.
ModificadaAlta (7.2)0.48%—Agnitum Outpost FirewallLavasoft Personal FirewallNovell Client Firewall21/7/200616/6/2026
Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and…
ModificadaAlta (7.2)0.37%—Slava Astashonok Fprobe31/12/200416/6/2026
Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors.
Orbitaley — Vulnerabilidades