Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Iris 88 Firmware | 14/11/2019 | 17/6/2026 | The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Flair Z1 Firmware | 14/11/2019 | 17/6/2026 | The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable… | |
| Modificada | Baja (3.3) | 0.25% | — | Lavamobiles Z61 Firmware | 14/11/2019 | 17/6/2026 | The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and… | |
| Modificada | Media (6.1) | 0.87% | — | Lavalite | 13/11/2019 | 17/6/2026 | XSS exists in Lavalite CMS 5.7 via the admin/profile name or designation field. | |
| Modificada | Media (5.4) | 0.60% | — | Lavalite | 10/10/2019 | 17/6/2026 | LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen. | |
| Modificada | Media (5.4) | 0.67% | — | Lavalite | 5/9/2018 | 17/6/2026 | LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit. | |
| Modificada | Alta (8.8) | 2.5% | — | Linaro LavaDebian Linux | 19/6/2018 | 17/6/2026 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of use of yaml.load() instead of yaml.safe_load() when parsing user data, remote code execution can occur. | |
| Modificada | Media (6.5) | 1.5% | — | Linaro LavaDebian Linux | 19/6/2018 | 17/6/2026 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for URLs in the submit page, a user can forge an HTTP request that will force lava-server-gunicorn to return any file on the server that is readable by lavaserver and valid yaml. | |
| Modificada | Media (6.5) | 0.89% | — | Linaro Lava | 19/6/2018 | 17/6/2026 | An issue was discovered in Linaro LAVA before 2018.5.post1. Because of support for file: URLs, a user can force lava-server-gunicorn to download any file from the filesystem if it's readable by lavaserver and valid yaml. | |
| Modificada | Media (5.4) | 0.73% | — | Lavalite | 3/1/2018 | 17/6/2026 | LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code. | |
| Modificada | Crítica (9.8) | 2.6% | — | Lavalink Ether-serial Link Firmware | 11/10/2017 | 17/6/2026 | An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by… | |
| Modificada | Media (5.4) | 0.27% | — | Teamlava Fashion Story\ | 19/10/2014 | 17/6/2026 | The Fashion Story: Neon 90's (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 71% | 💥 Exploit | Lavague | 11/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the views_path parameter. | |
| Modificada | Alta (7.2) | 0.48% | — | Agnitum Outpost FirewallLavasoft Personal FirewallNovell Client Firewall | 21/7/2006 | 16/6/2026 | Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and… | |
| Modificada | Alta (7.2) | 0.37% | — | Slava Astashonok Fprobe | 31/12/2004 | 16/6/2026 | Unknown local vulnerability in the "change user" feature of Slava Astashonok Fprobe 1.0.5 and earlier has unknown impact and attack vectors. |