Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
1806 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.2) | 0.38% | — | SqliteAIMicrosoft Windows C RuntimeAI | 4/6/2026 | 22/7/2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command… | |
| Aplazada | Media (5.1) | 0.17% | — | Soliloquy LiteAI | 4/6/2026 | 22/7/2026 | WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_title parameter,… | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+53 | 1/6/2026 | 22/7/2026 | Memory corruption while using Strongbox due to buffer overflow. | |
| Analizada | Alta (8.8) | 0.07% | — | Qualcomm Cq8750m FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+53 | 1/6/2026 | 22/7/2026 | Memory corruption while using Strongbox due to missing bounds check. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+214 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing fastboot commands to set display mode. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm C-v2x 9150 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s Firmware+269 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with improperly formatted input. | |
| Analizada | Alta (7.1) | 0.06% | — | Qualcomm Snapdragon 460 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 2 Mobile Platform FirmwareQualcomm Snapdragon 4 GEN 1 Mobile Platform FirmwareQualcomm Smart Audio 400 Platform Firmware+213 | 1/6/2026 | 22/7/2026 | Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+215 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot commands with invalid input. | |
| Analizada | Alta (8.2) | 0.07% | 💥 PoC | Qualcomm Ar9380 FirmwareQualcomm Csr8811 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+242 | 1/6/2026 | 22/7/2026 | Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Ar8031 FirmwareQualcomm Ar8035 FirmwareQualcomm Cologne FirmwareQualcomm Cq7790 Firmware+211 | 1/6/2026 | 22/7/2026 | Memory corruption while processing fastboot OEM commands. | |
| Analizada | Alta (7.2) | 0.10% | — | Qualcomm Qca6391 FirmwareQualcomm Qca6564au FirmwareQualcomm Qca6574 FirmwareQualcomm Qca6574a Firmware+269 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing display command line information due to improper initialization of a variable. | |
| Analizada | Media (6.4) | 0.06% | — | Qualcomm Snapdragon G1 GEN 2 Gaming Platform FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm C-v2x 9150 FirmwareQualcomm Cq7790 Firmware+232 | 1/6/2026 | 22/7/2026 | Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Cologne FirmwareQualcomm Cq7790 FirmwareQualcomm Cq8725s FirmwareQualcomm Cq8750m Firmware+137 | 1/6/2026 | 22/7/2026 | Memory Corruption when writing to invalid memory locations occurs due to heap memory exhaustion during secure data initialization. | |
| Analizada | Alta (7.8) | 0.07% | — | Qualcomm Snapdragon 480 5G Mobile Platform FirmwareQualcomm Snapdragon 480+ 5G Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 1 Mobile Platform FirmwareQualcomm Snapdragon 6 GEN 3 Mobile Platform Firmware+261 | 1/6/2026 | 22/7/2026 | Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | |
| Aplazada | Media (5.3) | 0.31% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpmet Elementskit Elementor Addons LiteAI | 27/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6. | |
| Aplazada | Alta (7.2) | 0.44% | — | Litespeedtech Litespeed CacheAI | 27/5/2026 | 17/6/2026 | The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to… | |
| Aplazada | Media (4.3) | 0.18% | — | CDN Linker LiteAI | 27/5/2026 | 17/6/2026 | The CDN Linker lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the ossdl_off_options() function. This makes it possible for unauthenticated attackers to update the plugin's settings — including the… | |
| Analizada | Media (6.5) | 7.1% | ⚠ Explotación activa💥 Exploit | Encode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+4 | 26/5/2026 | 1/10/2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make… | |
| Modificada | Alta (7.8) | 0.26% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 26/5/2026 | 2/10/2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wordpress Ultimate Form Builder LiteAI | 23/5/2026 | 23/7/2026 | WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the… | |
| Modificada | Alta (8.7) | 0.82% | 💥 PoC | Litellm | 21/5/2026 | 23/7/2026 | LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full… | |
| Modificada | Alta (8.7) | 1.3% | 💥 PoC | Litellm | 21/5/2026 | 23/7/2026 | LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only… | |
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 21/5/2026 | 23/7/2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been… | |
| Modificada | Media (6.5) | 0.57% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 21/5/2026 | 1/9/2026 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to… |