Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 1.0% | ⚠ Explotación activa💥 PoC | Litespeedtech Litespeed Cpanel PluginLitespeedtech Litespeed WHM Plugin | 21/5/2026 | 7/10/2026 | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsonapi_func=redisAble" /var/cpanel/logs /usr/local/cpanel/logs/ 2>/dev/null in Bash. If you get no output, you have not been… | |
| Modificada | Media (6.5) | 0.58% | — | Opensuse LibsolvRedhat Hardened ImagesRedhat Openshift Container PlatformRedhat Satellite+2 | 20/5/2026 | 1/9/2026 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service… | |
| Aplazada | Alta (7.3) | 0.34% | — | NET Statsd LiteAI | 18/5/2026 | 19/6/2026 | Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. Note that version 0.9.0 fixed a similar issue CVE-2026-46719 for metric names. | |
| Aplazada | Baja (2) | 0.41% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to… | |
| Aplazada | Baja (2) | 0.33% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A weakness has been identified in linlinjava litemall up to 1.8.0. Affected is an unknown function of the component Admin Endpoint. Executing a manipulation can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. Multiple… | |
| Aplazada | Media (5.5) | 0.41% | — | Linlinjava LitemallAI | 18/5/2026 | 17/6/2026 | A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exploitation of the… | |
| Aplazada | Media (6.5) | 0.36% | — | NET Statsd LiteAI | 16/5/2026 | 19/6/2026 | Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections. The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject additional statsd metrics. | |
| Aplazada | Media (6.4) | 0.35% | — | Envira Gallery LiteAI | 14/5/2026 | 17/6/2026 | The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in the update_gallery_data() function and improper output escaping in the gallery_init() function. The… | |
| Aplazada | Alta (8.5) | 0.36% | — | Aman Views Views FOR Wpforms LiteAI | 12/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPForms views-for-wpforms-lite allows Blind SQL Injection.This issue affects Views for WPForms: from n/a through <= 3.4.6. | |
| Aplazada | Alta (8.8) | 0.23% | — | E-kalite Software Turboard For-sAI | 12/5/2026 | 17/6/2026 | Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation. This issue affects Turboard FOR-S: from 7.01.2026 before 18.02.2026. | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa💥 PoC | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (6.5) | 0.48% | — | NET Cidr Lite Project NET Cidr LiteAI | 10/5/2026 | 24/7/2026 | Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass. Mask forms like "/00" and "/01" pass validation and parse to the same prefix as their unpadded value. See also CVE-2026-45190. | |
| Aplazada | Media (6.5) | 0.48% | — | NET Cidr Lite Project NET Cidr LiteAI | 10/5/2026 | 24/7/2026 | Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass. Inputs containing a trailing newline or non-ASCII digit characters pass the validators but are then re-encoded by the parser to a different address than the input string spelled.… | |
| Aplazada | Media (5.1) | 0.19% | — | Motopress Hotel Booking LiteAI | 10/5/2026 | 25/7/2026 | Motopress Hotel Booking Lite 4.2.4 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting payloads in accommodation type fields. Attackers can inject script tags through the title and excerpt parameters when creating accommodation types, which… | |
| Analizada | Alta (8.7) | 93% | ⚠ Explotación activa💥 Exploit | LitellmRedhat Openshift AI | 8/5/2026 | 15/7/2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request… | |
| Analizada | Crítica (9.3) | 5.8% | ⚠ Explotación activa💥 Exploit | Litellm | 8/5/2026 | 15/7/2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query text instead of passing it as a separate parameter. An unauthenticated attacker could… | |
| Modificada | Alta (8.6) | 0.66% | 💥 PoC | Litellm | 8/5/2026 | 15/7/2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-supplied prompt templates and rendered them without sandboxing. A crafted template could run arbitrary code inside the LiteLLM Proxy process.… | |
| Analizada | Alta (7) | 0.09% | — | Qualcomm Video Collaboration VC1 Platform FirmwareQualcomm Video Collaboration VC3 Platform FirmwareQualcomm Qxm1083 FirmwareQualcomm Qxm1086 Firmware+96 | 4/5/2026 | 7/10/2026 | Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level. | |
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Snapdragon X65 5G Modem-rf FirmwareQualcomm Snapdragon X72 5G Modem-rf FirmwareQualcomm Snapdragon X75 5G Modem-rf FirmwareQualcomm Srv1h Firmware+253 | 4/5/2026 | 7/10/2026 | Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming. | |
| Analizada | Alta (7.5) | 0.18% | — | Qualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 Firmware+241 | 4/5/2026 | 7/10/2026 | Transient DOS when processing target power rate tables during channel configuration. | |
| Aplazada | Media (6.4) | 0.19% | — | Nextmove Lite Thank YOU Page WoocommerceAI | 2/5/2026 | 17/6/2026 | The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'xlwcty_current_date' shortcode in all versions up to, and including, 2.23.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.5) | 0.51% | — | Nextlevelbuilder GoclawAINextlevelbuilder Goclaw LiteAI | 30/4/2026 | 17/6/2026 | A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attack may be initiated remotely. The exploit has been published and may be used. Upgrading to version 3.9.0 mitigates this… | |
| Aplazada | Media (5.5) | 0.43% | — | Dubydu Sqlite-mcpAI | 28/4/2026 | 24/7/2026 | A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the… | |
| Aplazada | Media (6.4) | 0.26% | — | Image Source Control LiteAI | 20/4/2026 | 17/6/2026 | The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (7.5) | 0.48% | — | Anviz CX7 FirmwareAnviz CX2 Lite Firmware | 17/4/2026 | 17/6/2026 | Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH), allowing unauthorized state changes that can facilitate later compromise. |