Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

207 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.57%—Gradio Project Gradio5/5/202417/6/2026
Gradio before 4.20 allows credential leakage on Windows.
AplazadaMedia (4.3)0.20%—Netmix Radio StationAI26/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station.This issue affects Radio Station: from n/a through <= 2.5.7.
AplazadaMedia (5.4)0.32%—Softlabbd Radio PlayerAI25/4/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
AplazadaMedia (5.4)0.35%—Softlabbd Radio PlayerAI17/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
AnalizadaAlta (7.5)9.3%💥 ExploitGradio Project Gradio16/4/202417/6/2026
An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block` class, an attacker can copy any file on…
AnalizadaMedia (6.5)1.8%💥 ExploitGradio Project Gradio16/4/202417/6/2026
An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a…
AplazadaMedia (6.3)0.68%—GradioAIAutomatic1111 Stable-diffusion-webuiAI12/4/202417/6/2026
stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on…
ModificadaAlta (7.5)0.55%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast10/4/202417/6/2026
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1.
AnalizadaAlta (7.5)85%💥 ExploitGradio Project Gradio10/4/202417/6/2026
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the…
ModificadaMedia (5.4)0.36%—Wpmilitary WP Radio10/4/202417/6/2026
The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in all versions up to, and including, 3.1.9. This makes it possible for authenticated attackers, with subscriber…
ModificadaMedia (5.4)0.38%—Wpmilitary WP Radio10/4/202417/6/2026
The WP Radio – Worldwide Online Radio Stations Directory for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's settings in all versions up to, and including, 3.1.9 due to insufficient input sanitization and output escaping as well as insufficient access control on the…
ModificadaMedia (5.4)0.34%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
ModificadaAlta (7.6)0.48%—Sonaar MP3 Audio Player FOR Music, Radio & Podcast29/3/202417/6/2026
Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1.
AnalizadaMedia (5.9)0.50%—Gradio Project Gradio29/3/202417/6/2026
A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability arises from the use of a direct comparison operation (`app.auth[username] == password`) to validate user credentials, which can be exploited to guess passwords based on…
AnalizadaAlta (8.2)2.0%💥 PoCGradio Project Gradio27/3/202417/6/2026
A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization of special elements used in a command. This vulnerability allows attackers to execute unauthorized commands, potentially leading to unauthorized modification of the base…
ModificadaMedia (5.4)0.34%—Softlabbd Radio Player27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73.
AnalizadaMedia (6.5)0.42%—Gradio Project Gradio27/3/202417/6/2026
An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls` set through the `X-Direct-Url` header in requests to the `/` and `/config` routes, allowing the addition of…
AplazadaMedia (6.5)0.48%—Softlabbd Radio PlayerAI26/3/202417/6/2026
Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73.
AnalizadaMedia (4.3)0.35%—Gradio Project Gradio21/3/202417/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk…
ModificadaCrítica (9.4)0.96%—Gradio Project Gradio5/2/202417/6/2026
A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.
ModificadaAlta (7.5)28%💥 ExploitGradio Project Gradio22/12/202317/6/2026
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an…
ModificadaAlta (8.1)1.7%💥 PoCGradio Project Gradio14/12/202317/6/2026
Command Injection in GitHub repository gradio-app/gradio prior to main.
ModificadaAlta (8.8)0.24%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
ModificadaMedia (6.5)0.36%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
ModificadaCrítica (9.8)0.79%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
Orbitaley — Vulnerabilidades