Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Clever Html5 Radio Player With HistoryAI | 19/4/2025 | 17/6/2026 | The CLEVER - HTML5 Radio Player With History - Shoutcast and Icecast - Elementor Widget Addon plugin for WordPress is vulnerable to arbitrary file read due to insufficient file path validation in the 'history.php' file in all versions up to, and including, 2.4. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.1) | 0.19% | — | Sudavar Codescar Radio WidgetAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sudavar Codescar Radio Widget codescar-radio-widget allows Stored XSS.This issue affects Codescar Radio Widget: from n/a through <= 0.4.2. | |
| Aplazada | Media (4.3) | 0.40% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.9.4. | |
| Analizada | Alta (7.5) | 0.72% | — | Gradio Project Gradio | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and… | |
| Modificada | Alta (7.5) | 0.79% | — | Gradio Video | 20/3/2025 | 17/6/2026 | A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render… | |
| Analizada | Media (6.1) | 0.74% | 💥 Exploit | Gradio Project Gradio | 20/3/2025 | 17/6/2026 | An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site. | |
| Aplazada | Media (5.3) | 0.69% | — | Gradio-app GradioAI | 20/3/2025 | 17/6/2026 | A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow users from reading certain files, is flawed. Specifically, while the application correctly blocks access to paths like… | |
| Analizada | Alta (8.2) | 0.72% | — | Gradio Project Gradio | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty… | |
| Modificada | Alta (7.5) | 1.1% | — | Gradio Project Gradio | 20/3/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the use of a regular expression `^(?:\s*now\s*(?:-\s*(\d+)\s*([dmhs]))?)?\s*$` to process user input.… | |
| Analizada | Alta (7.5) | 0.65% | — | Gradio Project Gradio | 20/3/2025 | 17/6/2026 | A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing… | |
| Aplazada | Media (6.1) | 0.31% | — | Nradio N8-180AI | 3/2/2025 | 17/6/2026 | An issue was discovered in NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to XSS via the 2.4 GHz and 5 GHz name parameters, allowing an attacker to execute JavaScript within the context of the current user by injecting JavaScript into the SSID field. If an… | |
| Aplazada | Media (4.8) | 15% | — | Nradio N8-180AI | 3/2/2025 | 17/6/2026 | An issue was discovered on NRadio N8-180 NROS-1.9.2.n3.c5 devices. The /cgi-bin/luci/nradio/basic/radio endpoint is vulnerable to command injection via the 2.4 GHz and 5 GHz name parameters, allowing a remote attacker to execute arbitrary OS commands on the device (with root-level permissions) via crafted input. | |
| Aplazada | Alta (7.1) | 0.26% | — | Oneteamsoftware Radio Buttons AND Swatches FOR WoocommerceAI | 31/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in oneteamsoftware Radio Buttons and Swatches for WooCommerce variations-radio-buttons-for-woocommerce allows Reflected XSS.This issue affects Radio Buttons and Swatches for WooCommerce: from n/a through <= 1.1.20. | |
| Aplazada | Media (6.4) | 0.38% | — | WpradioAI | 31/1/2025 | 17/6/2026 | The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpradio_player' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.9) | 0.38% | — | Yesstreamingdev Shoutcast AND Icecast Html5 WEB Radio PlayerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yesstreamingdev Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com allows Stored XSS.This issue affects Shoutcast and Icecast HTML5 Web… | |
| Analizada | Alta (8.7) | 0.98% | — | Gradio Project Gradio | 14/1/2025 | 17/6/2026 | Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter case of a blocked file or directory path. This vulnerability… | |
| Modificada | Alta (8.8) | 0.33% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.8. | |
| Aplazada | Alta (7.2) | 5.5% | 💥 Exploit | Princeahmed Radio-playerAI | 16/12/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.83. | |
| Analizada | Alta (8.8) | 0.43% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10. | |
| Aplazada | Media (6.4) | 0.26% | — | Luna Radio PlayerAI | 5/12/2024 | 17/6/2026 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in versions up to, and including, 6.24.11.07 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Analizada | Media (5.4) | 0.34% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 19/11/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Alta (7.5) | 1.1% | — | Luna Radio PlayerAI | 13/11/2024 | 17/6/2026 | The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Analizada | Media (6.5) | 0.69% | — | Gradio Project Gradio | 6/11/2024 | 17/6/2026 | Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as a part of Gradio application to preview file content, an attacker with access to the application might abuse these components to read arbitrary files from the application… | |
| Analizada | Media (6.5) | 0.47% | — | Gradio Project Gradio | 4/11/2024 | 17/6/2026 | In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive… | |
| Aplazada | Media (6.4) | 0.29% | — | Shoutcast Icecast Html5 Radio PlayerAI | 25/10/2024 | 17/6/2026 | The Shoutcast Icecast HTML5 Radio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'html5radio' shortcode in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… |