Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
1810 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.75% | — | Angrybyte Wordpress Exit BOX Lite | 5/6/2023 | 16/6/2026 | A vulnerability, which was classified as problematic, has been found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this issue is some unknown functionality of the file wordpress-exit-box-lite.php. The manipulation leads to information disclosure. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Alta (8.8) | 0.43% | — | Angrybte Wordpress Exit BOX Lite | 5/6/2023 | 16/6/2026 | A vulnerability classified as problematic was found in Exit Box Lite Plugin up to 1.06 on WordPress. Affected by this vulnerability is the function exitboxadmin of the file wordpress-exit-box-lite.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. Upgrading to version 1.10… | |
| Modificada | Crítica (9.8) | 0.87% | — | Elite Webfax | 2/6/2023 | 17/6/2026 | ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote attacker can inject SQL commands into the input field of the login page to perform arbitrary system commands, disrupt service or terminate service. | |
| Modificada | Alta (7.1) | 0.30% | — | ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+13 | 30/5/2023 | 17/6/2026 | There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could delete some system files without user permission. | |
| Modificada | Baja (3.3) | 0.29% | — | ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+13 | 30/5/2023 | 17/6/2026 | There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could start a non-public interface of an application without user permission. | |
| Modificada | Alta (7.1) | 0.30% | — | ZTE Blade A52 FirmwareZTE Blade A51 FirmwareZTE Blade A3 Lite FirmwareZTE Blade A5 2020 Firmware+13 | 30/5/2023 | 17/6/2026 | There is an unauthorized access vulnerability in some ZTE mobile phones. If a malicious application is installed on the phone, it could overwrite some system configuration files and user installers without user permission. | |
| Modificada | Alta (8.8) | 0.26% | — | Litespeedtech Litespeed Cache | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LiteSpeed Technologies LiteSpeed Cache plugin <= 5.3 versions. | |
| Modificada | Crítica (9.8) | 1.6% | 💥 PoC | Sqlite Jdbc Project Sqlite Jdbc | 23/5/2023 | 17/6/2026 | SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2. | |
| Modificada | Alta (8.1) | 0.66% | — | Fit2cloud Cloudexplorer Lite | 23/5/2023 | 17/6/2026 | Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |
| Modificada | Media (4.9) | 0.68% | — | Fit2cloud Cloudexplorer Lite | 23/5/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0. | |
| Modificada | Media (5.4) | 0.38% | — | Lavalite | 18/5/2023 | 17/6/2026 | LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Crítica (9.8) | 0.87% | — | Lavalite | 12/5/2023 | 17/6/2026 | LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning. | |
| Modificada | Media (6.1) | 0.59% | — | Lavalite | 12/5/2023 | 9/7/2026 | LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack. | |
| Modificada | Media (5.4) | 0.36% | — | Custom4web Affiliate Links Lite | 10/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Custom4Web Affiliate Links Lite plugin <= 2.5 versions. | |
| Modificada | Alta (7.5) | 2.2% | — | Sqlite | 9/5/2023 | 17/6/2026 | An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function. | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm Wcn3998 FirmwareQualcomm Qca6390 FirmwareQualcomm Wcn685x-5 FirmwareQualcomm Wcn685x-1 Firmware+161 | 2/5/2023 | 17/6/2026 | Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool. | |
| Modificada | Alta (7.8) | 0.18% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8052 Firmware+216 | 2/5/2023 | 17/6/2026 | Memory corruption in Graphics while importing a file. | |
| Modificada | Media (5.5) | 0.18% | — | HP Elite Dragonfly G3 FirmwareHP Dragonfly Folio G3 FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX Firmware+87 | 28/4/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow loss of integrity. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Media (5.4) | 0.36% | — | Machothemes Regina Lite | 25/4/2023 | 17/6/2026 | Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes Regina Lite theme <= 2.0.7 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Trinitronic Nice Paypal Button Lite | 23/4/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <= 1.3.5 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Codebangers ALL IN ONE Time Clock Lite | 23/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions. | |
| Modificada | Crítica (9.8) | 0.82% | — | Litextension Leurlrewrite | 17/4/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Apq8016 FirmwareQualcomm Apq8017 Firmware+349 | 13/4/2023 | 17/6/2026 | Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target. | |
| Modificada | Alta (7.5) | 0.41% | — | Qualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+181 | 13/4/2023 | 17/6/2026 | Information disclosure due to buffer over-read in Bluetooth Host while A2DP streaming. | |
| Modificada | Alta (7.8) | 0.12% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+221 | 13/4/2023 | 17/6/2026 | Memory corruption due to improper validation of array index in User Identity Module when APN TLV length is greater than command length. |