Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
207 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.57% | — | Gradio Project Gradio | 5/5/2024 | 17/6/2026 | Gradio before 4.20 allows credential leakage on Windows. | |
| Aplazada | Media (4.3) | 0.20% | — | Netmix Radio StationAI | 26/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station.This issue affects Radio Station: from n/a through <= 2.5.7. | |
| Aplazada | Media (5.4) | 0.32% | — | Softlabbd Radio PlayerAI | 25/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (5.4) | 0.35% | — | Softlabbd Radio PlayerAI | 17/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Analizada | Alta (7.5) | 9.3% | 💥 Exploit | Gradio Project Gradio | 16/4/2024 | 17/6/2026 | An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block` class, an attacker can copy any file on… | |
| Analizada | Media (6.5) | 1.8% | 💥 Exploit | Gradio Project Gradio | 16/4/2024 | 17/6/2026 | An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a… | |
| Aplazada | Media (6.3) | 0.68% | — | GradioAIAutomatic1111 Stable-diffusion-webuiAI | 12/4/2024 | 17/6/2026 | stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on… | |
| Modificada | Alta (7.5) | 0.55% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1. | |
| Analizada | Alta (7.5) | 85% | 💥 Exploit | Gradio Project Gradio | 10/4/2024 | 17/6/2026 | gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the… | |
| Modificada | Media (5.4) | 0.36% | — | Wpmilitary WP Radio | 10/4/2024 | 17/6/2026 | The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with subscriber… | |
| Modificada | Media (5.4) | 0.38% | — | Wpmilitary WP Radio | 10/4/2024 | 17/6/2026 | The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping as well as insufficient access control on the… | |
| Modificada | Media (5.4) | 0.34% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Modificada | Alta (7.6) | 0.48% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Analizada | Media (5.9) | 0.50% | — | Gradio Project Gradio | 29/3/2024 | 17/6/2026 | A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability arises from the use of a direct comparison operation (`app.auth[username] == password`) to validate user credentials, which can be exploited to guess passwords based on… | |
| Analizada | Alta (8.2) | 2.0% | 💥 PoC | Gradio Project Gradio | 27/3/2024 | 17/6/2026 | A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization of special elements used in a command. This vulnerability allows attackers to execute unauthorized commands, potentially leading to unauthorized modification of the base… | |
| Modificada | Media (5.4) | 0.34% | — | Softlabbd Radio Player | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73. | |
| Analizada | Media (6.5) | 0.42% | — | Gradio Project Gradio | 27/3/2024 | 17/6/2026 | An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls` set through the `X-Direct-Url` header in requests to the `/` and `/config` routes, allowing the addition of… | |
| Aplazada | Media (6.5) | 0.48% | — | Softlabbd Radio PlayerAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Analizada | Media (4.3) | 0.35% | — | Gradio Project Gradio | 21/3/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk… | |
| Modificada | Crítica (9.4) | 0.96% | — | Gradio Project Gradio | 5/2/2024 | 17/6/2026 | A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request. | |
| Modificada | Alta (7.5) | 28% | 💥 Exploit | Gradio Project Gradio | 22/12/2023 | 17/6/2026 | Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an… | |
| Modificada | Alta (8.1) | 1.7% | 💥 PoC | Gradio Project Gradio | 14/12/2023 | 17/6/2026 | Command Injection in GitHub repository gradio-app/gradio prior to main. | |
| Modificada | Alta (8.8) | 0.24% | — | Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+11 | 26/10/2023 | 17/6/2026 | The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site. | |
| Modificada | Media (6.5) | 0.36% | — | Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+11 | 26/10/2023 | 17/6/2026 | The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters. | |
| Modificada | Crítica (9.8) | 0.79% | — | Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+11 | 26/10/2023 | 17/6/2026 | The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter. |