Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1811 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.29% | — | Finale LiteAI | 27/8/2026 | 28/8/2026 | The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary post ID, allowing any authenticated user (Subscriber and above) to read the Finale Lite WordPress plugin before 2.21.0's campaign configuration and… | |
| Aplazada | Media (4) | 0.19% | — | SqliteAI | 25/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via… | |
| Aplazada | Crítica (9.8) | 0.90% | — | WS Form LiteAI | 22/8/2026 | 24/8/2026 | The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP… | |
| Aplazada | Media (4.2) | 0.12% | — | Litextension Wordpress PluginAI | 21/8/2026 | 26/8/2026 | The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a crafted link (CSRF). | |
| Aplazada | Media (5.3) | 0.53% | — | WC Product Table LiteAI | 16/8/2026 | 20/8/2026 | The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' shortcode attribute exposed through the unauthenticated wcpt_ajax() AJAX handler. The handler is registered for wp_ajax_nopriv_wcpt_ajax, JSON-decodes attacker-supplied… | |
| Aplazada | Crítica (9.2) | 0.76% | — | Laravel SocialiteAI | 14/8/2026 | 24/9/2026 | Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired… | |
| Aplazada | Crítica (9.8) | 0.85% | — | Ajax Search LiteAI | 7/8/2026 | 26/8/2026 | The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before 4.14.5 or , this can be leveraged to… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langchain Langgraph Checkpoint PostgresAILangchain Langgraph Checkpoint SqliteAI | 6/8/2026 | 10/9/2026 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string… | |
| Aplazada | Alta (7.5) | 0.19% | — | Redyx Payment Gateway FOR Redsys AND Woocommerce LiteAI | 6/8/2026 | 26/8/2026 | The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a payment-confirmation callback and complete their own… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Ajax Search LiteAI | 6/8/2026 | 12/8/2026 | Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions. | |
| Analizada | Alta (7.6) | 0.15% | — | Qualcomm Sm6225p FirmwareQualcomm Sm6450p FirmwareQualcomm Sm6475p FirmwareQualcomm Sm6475q Firmware+207 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration. | |
| Analizada | Crítica (9.6) | 0.19% | — | Qualcomm Sm7550p FirmwareQualcomm Sm7635p FirmwareQualcomm Sm7675 FirmwareQualcomm Sm7675p Firmware+197 | 4/8/2026 | 6/8/2026 | Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values. | |
| Analizada | Alta (7.4) | 0.16% | — | Qualcomm Orne FirmwareQualcomm Palawan25 FirmwareQualcomm Pandeiro FirmwareQualcomm Qln1083bd Firmware+50 | 4/8/2026 | 6/8/2026 | Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size. | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Sdx57m FirmwareQualcomm Sdx61 FirmwareQualcomm Sdx71m FirmwareQualcomm Sm6650p Firmware+124 | 4/8/2026 | 6/8/2026 | Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities. | |
| Analizada | Alta (8.1) | 0.21% | — | Qualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 FirmwareQualcomm Fastconnect 6200 Firmware+139 | 4/8/2026 | 6/8/2026 | Cryptographic Issue while processing registration requests with malformed or missing authentication parameters. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+143 | 4/8/2026 | 6/8/2026 | Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling. | |
| Analizada | Media (6.5) | 0.17% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Csra6620 FirmwareQualcomm Csra6640 Firmware+140 | 4/8/2026 | 6/8/2026 | Information Disclosure when processing wireless network channel switch information with improperly formatted length fields. | |
| Aplazada | Media (5.9) | 0.38% | — | LitestarAI | 3/8/2026 | 10/9/2026 | Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware trusts the X-Forwarded-Host header as a… | |
| Pendiente de análisis | Media (6.9) | 0.64% | — | Sharp Network Scanner ToolAISharp Network Scanner Tool LiteAI | 3/8/2026 | 3/8/2026 | Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly.… | |
| Aplazada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social LoginAI | 2/8/2026 | 12/8/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload without verifying the JWT signature against Apple's public keys or… | |
| Pendiente de análisis | Alta (8.8) | 0.55% | — | Eaton Tripp Lite PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device. | |
| Pendiente de análisis | Alta (8.3) | 0.58% | — | Eaton Tripp Lite Series PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. | |
| Pendiente de análisis | Alta (8.6) | 0.66% | — | Eaton Tripp Lite PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. | |
| Pendiente de análisis | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite HomeAI | 29/7/2026 | 30/7/2026 | Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this… | |
| Pendiente de análisis | Alta (8.1) | 0.78% | — | Autel Maxicharger AC Elite HomeAI | 29/7/2026 | 30/7/2026 | Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific… |