Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1806 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.40% | — | Litellm | 21/6/2026 | 24/6/2026 | A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_openapi_spec_async of the file litellm/proxy/_experimental/mcp_server/openapi_to_mcp_generator.py of the component MCP OpenAPI Spec Loader. This manipulation of the argument spec_path causes server-side… | |
| Analizada | Baja (2.1) | 0.40% | — | Litellm | 21/6/2026 | 24/6/2026 | A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the file enterprise/enterprise_hooks/banned_keywords.py of the component Completions Interface. The manipulation of the argument prompt results in incorrect authorization. The attack may be performed… | |
| Analizada | Baja (2.1) | 0.57% | — | Litellm | 21/6/2026 | 24/6/2026 | A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_openid of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Authentication Flow. The manipulation leads to session expiration. The attack is possible to be carried out remotely.… | |
| Analizada | Media (5.5) | 0.80% | — | Litellm | 21/6/2026 | 24/6/2026 | A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly… | |
| Analizada | Baja (2.1) | 0.40% | — | Litellm | 21/6/2026 | 24/6/2026 | A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery.… | |
| Modificada | Media (5.5) | 1.0% | — | Litellm | 21/6/2026 | 15/7/2026 | A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.40% | — | Litellm | 21/6/2026 | 24/6/2026 | A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database API Key Generator. Performing a manipulation results in session expiration. The attack may be initiated remotely. The… | |
| Analizada | Baja (1.3) | 0.43% | — | Litellm | 21/6/2026 | 24/6/2026 | A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulation leads to improper authorization. The attack can be launched remotely. A high complexity level is associated with this… | |
| Analizada | Baja (2.1) | 0.57% | — | Litellm | 21/6/2026 | 24/6/2026 | A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component Admin Key Handler. This manipulation causes improper authorization. The attack can be initiated remotely. The exploit… | |
| Analizada | Alta (7.7) | 0.33% | — | Radvd.litech Radvd | 19/6/2026 | 26/6/2026 | radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data… | |
| Analizada | Alta (8.8) | 0.49% | — | Zcontent ZAP Calendar Lite | 19/6/2026 | 21/8/2026 | Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with crafted SQL payloads to extract sensitive… | |
| Aplazada | Media (6.4) | 0.20% | — | Slideshow Gallery LiteAI | 18/6/2026 | 18/6/2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortcode attribute in all versions up to, and including, 1.8.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.31% | — | Event KOI LiteAI | 18/6/2026 | 18/6/2026 | The Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.13.1 via the get_events. This makes it possible for unauthenticated attackers to extract sensitive data including virtual meeting… | |
| Pendiente de análisis | Media (4.3) | 0.22% | — | Redhat SatelliteAIRedhat KatelloAI | 17/6/2026 | 4/8/2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Permalink Manager LiteAI | 17/6/2026 | 17/6/2026 | The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (4.7) | 0.16% | — | WP Migrate LiteAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in WP Migrate Lite <= 2.7.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wcproducttable Woocommerce Product Table LiteAI | 15/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 4.6.3 versions. | |
| Aplazada | Alta (8.7) | 0.64% | — | HB Audio Gallery LiteAI | 15/6/2026 | 17/6/2026 | WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access sensitive files… | |
| Analizada | Alta (8.5) | 0.81% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 14/6/2026 | 23/7/2026 | LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running CloudLinux/CageFS, as exploited in the wild in May 2026. | |
| Aplazada | Media (6.5) | 0.44% | — | BoxliteAI | 10/6/2026 | 23/7/2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite… | |
| Aplazada | Crítica (9.6) | 0.78% | — | BoxliteAI | 10/6/2026 | 23/7/2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users to specify the OCI image used by containers in the sandbox. However, when processing tar entries in OCI images, Boxlite… | |
| Aplazada | Crítica (10) | 0.48% | — | BoxliteAI | 10/6/2026 | 23/7/2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not restrict the kernel capabilities available inside the container, malicious code can remount the directory in rw mode,… | |
| Analizada | Alta (8.5) | 0.18% | — | Sqlite | 9/6/2026 | 23/7/2026 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an… | |
| Analizada | Alta (8.5) | 0.29% | — | Sqlite | 9/6/2026 | 23/7/2026 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in… | |
| Aplazada | Media (6.4) | 0.35% | — | Recipe Card Blocks LiteAI | 8/6/2026 | 23/7/2026 | The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into… |