Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
94 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.32% | — | Appsbd Vite CouponAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon vite-coupon allows Remote Code Inclusion.This issue affects Vite Coupon: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.3) | 40% | 💥 Exploit | Vitejs ViteAI | 3/4/2025 | 17/6/2026 | Vite is a frontend tooling framework for javascript. The contents of arbitrary files can be returned to the browser. By adding ?.svg with ?.wasm?init or with sec-fetch-dest: script header, the server.fs.deny restriction was able to bypass. This bypass is only possible if the file is smaller than… | |
| Aplazada | Alta (8.8) | 0.49% | — | Appsbd Vitepos LiteAI | 1/4/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in appsbd Vitepos vitepos-lite allows Authentication Abuse.This issue affects Vitepos: from n/a through <= 3.1.4. | |
| Analizada | Alta (7.5) | 65% | ⚠ Explotación activa💥 Exploit | Vitejs Vite | 31/3/2025 | 17/6/2026 | Vite is a frontend tooling framework for javascript. Vite exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the network (using --host or server.host config option) are affected. This vulnerability is fixed in 6.2.4, 6.1.3, 6.0.13, 5.4.16, and… | |
| Aplazada | Media (4.3) | 0.49% | — | Devitems Support GenixAI | 27/3/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in DevItems Support Genix support-genix-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Support Genix: from n/a through <= 1.4.11. | |
| Aplazada | Media (6.5) | 0.36% | — | Chris Taylor Wordpress-mu-secure-invitesAI | 26/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Taylor Secure Invites wordpress-mu-secure-invites allows Reflected XSS.This issue affects Secure Invites: from n/a through <= 1.3. | |
| Analizada | Alta (7.5) | 75% | 💥 Exploit | Vitejs Vite | 24/3/2025 | 17/6/2026 | Vite, a provider of frontend development tooling, has a vulnerability in versions prior to 6.2.3, 6.1.2, 6.0.12, 5.4.15, and 4.5.10. `@fs` denies access to files outside of Vite serving allow list. Adding `?raw??` or `?import&raw??` to the URL bypasses this limitation and returns the file content if it exists. This… | |
| Aplazada | Alta (7.1) | 0.37% | — | Pinal.shah Send-booking-invites-to-friendsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pinal.shah Send to a Friend Addon send-booking-invites-to-friends allows Reflected XSS.This issue affects Send to a Friend Addon: from n/a through <= 1.4.1. | |
| Aplazada | Media (6.5) | 0.34% | — | Appsbd Vitepos LiteAI | 22/2/2025 | 17/6/2026 | Missing Authorization vulnerability in appsbd Vitepos vitepos-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vitepos: from n/a through <= 3.1.3. | |
| Analizada | Alta (8.8) | 0.68% | — | Vitest.dev Vitest | 4/2/2025 | 17/6/2026 | Vitest is a testing framework powered by Vite. Affected versions are subject to arbitrary remote Code Execution when accessing a malicious website while Vitest API server is listening by Cross-site WebSocket hijacking (CSWSH) attacks. When `api` option is enabled (Vitest UI enables it), Vitest starts a WebSocket… | |
| Analizada | Alta (7.5) | 2.4% | 💥 Exploit | Vitest.dev Vitest | 4/2/2025 | 17/6/2026 | Vitest is a testing framework powered by Vite. The `__screenshot-error` handler on the browser mode HTTP server that responds any file on the file system. Especially if the server is exposed on the network by `browser.api.host: true`, an attacker can send a request to that handler from remote to get the content of… | |
| Analizada | Media (6.5) | 0.29% | — | Vitejs Vite | 20/1/2025 | 17/6/2026 | Vite is a frontend tooling framework for javascript. Vite allowed any websites to send any requests to the development server and read the response due to default CORS settings and lack of validation on the Origin header for WebSocket connections. This vulnerability is fixed in 6.0.9, 5.4.12, and 4.5.6. | |
| Aplazada | Media (4.9) | 0.44% | — | Linuxfoundation VitessAI | 3/12/2024 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user input. The result is that queries executed by Vitess can write HTML into the monitoring page at will. These pages are rendered using text/template… | |
| Aplazada | Media (6.4) | 0.64% | — | Vitejs ViteAI | 17/9/2024 | 17/6/2026 | Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` output format. The DOM Clobbering gadget in the module can lead to cross-site scripting (XSS) in web pages where scriptless… | |
| Aplazada | Media (4.8) | 1.1% | — | Vitejs ViteAI | 17/9/2024 | 17/6/2026 | Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access to files outside of Vite serving allow list. Adding `?import&raw` to the URL bypasses this limitation and returns the file content if it exists. This issue… | |
| Analizada | Media (6.1) | 0.31% | — | Teleogistic Invite Anyone | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Boone Gorges Invite Anyone allows Reflected XSS.This issue affects Invite Anyone: from n/a through 1.4.7. | |
| Aplazada | Alta (8.8) | 0.52% | — | Vitec AvediaserverAI | 15/5/2024 | 17/6/2026 | Insecure Permissions vulnerability in VITEC AvediaServer (Model avsrv-m8105) 8.6.2-1 allows a remote attacker to escalate privileges via a crafted script. | |
| Aplazada | Media (4.3) | 0.37% | — | Appsbd ViteposAI | 8/5/2024 | 17/6/2026 | Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1. | |
| Aplazada | Media (4.9) | 0.75% | — | Linuxfoundation VitessAI | 8/5/2024 | 17/6/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop that also keeps consuming memory and eventually will run out of memory. This vulnerability is fixed in 19.0.4, 18.0.5, and 17.0.7. | |
| Aplazada | Media (5.9) | 0.71% | — | Vitejs ViteAI | 4/4/2024 | 17/6/2026 | Vite (French word for "quick", pronounced /vit/, like "veet") is a frontend build tooling to improve the frontend development experience.`server.fs.deny` does not deny requests for patterns with directories. This vulnerability has been patched in version(s) 5.2.6, 5.1.7, 5.0.13, 4.5.3, 3.2.10 and 2.9.18. | |
| Modificada | Alta (7.5) | 0.78% | — | Vitejs Vite | 19/1/2024 | 17/6/2026 | Vite is a frontend tooling framework for javascript. The Vite dev server option `server.fs.deny` can be bypassed on case-insensitive file systems using case-augmented versions of filenames. Notably this affects servers hosted on Windows. This bypass is similar to CVE-2023-34092 -- with surface area reduced to hosts… | |
| Modificada | Media (6.5) | 0.33% | — | Sarveshmrao WP Discord Invite | 17/1/2024 | 17/6/2026 | The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions on their behalf by tricking a logged in administrator to submit a crafted request. | |
| Modificada | Media (6.1) | 1.00% | 💥 Exploit | Vitejs Vite | 4/12/2023 | 17/6/2026 | Vite is a website frontend framework. When Vite's HTML transformation is invoked manually via `server.transformIndexHtml`, the original request URL is passed in unmodified, and the `html` being transformed contains inline module scripts (`<script type="module">...</script>`), it is possible to inject arbitrary HTML… | |
| Modificada | Media (4.8) | 0.40% | — | Sarveshmrao WP Discord Invite | 6/11/2023 | 17/6/2026 | The WP Discord Invite WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Vitejs Vite | 1/6/2023 | 17/6/2026 | Vite provides frontend tooling. Prior to versions 2.9.16, 3.2.7, 4.0.5, 4.1.5, 4.2.3, and 4.3.9, Vite Server Options (`server.fs.deny`) can be bypassed using double forward-slash (//) allows any unauthenticated user to read file from the Vite root-path of the application including the default `fs.deny` settings… |