Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.94%—LavagueAI4/9/202610/9/2026
LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the…
AplazadaAlta (8.6)0.19%—Lavavo CD RipperAI22/3/202617/6/2026
Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Activation Name field. Attackers can craft a payload with controlled buffer data, NSEH jump instructions, and SEH…
AplazadaMedia (4.4)0.31%—Salavat CounterAI19/2/202617/6/2026
The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
AnalizadaAlta (8.8)0.46%—Lavalite13/2/202617/6/2026
LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based…
AplazadaAlta (8.5)0.17%—Lavasoft Adaware WEB CompanionAI5/2/202617/6/2026
Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious…
AnalizadaMedia (5.1)0.23%—Lavalite23/1/202614/7/2026
LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper output encoding in…
AplazadaCrítica (9)0.42%—Cristian Lavaque S2memberAI22/10/202529/9/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.
AplazadaAlta (7.3)0.29%—Lavasoft WEB CompanionAI9/10/202517/6/2026
Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with write access to the file system could potentially execute arbitrary code with elevated privileges by placing a malicious…
AnalizadaCrítica (9.3)0.50%—Hliu Llava20/3/202517/6/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthorized web actions or…
AnalizadaMedia (6.1)0.52%—Hliu Llava20/3/202517/6/2026
An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.
AnalizadaAlta (7.5)0.69%—Hliu Llava20/3/202517/6/2026
A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such as AWS metadata…
AnalizadaAlta (7.5)0.93%—Hliu Llava20/3/202517/6/2026
A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component.
ModificadaAlta (7.5)0.62%—Hliu Llava20/3/202517/6/2026
A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessible.
AplazadaMedia (5.9)0.29%—Lavacode Lava Ajax SearchAI11/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search lava-ajax-search allows Stored XSS.This issue affects Lava Ajax Search: from n/a through <= 1.1.9.
AplazadaAlta (7.1)0.32%—Cristian Lavaque S2memberAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member s2member allows Reflected XSS.This issue affects s2Member: from n/a through <= 241216.
AnalizadaMedia (6.1)0.43%—Clavaque S2member18/2/202517/6/2026
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it…
AplazadaMedia (5.4)0.16%—Slava Abakumov Buddypress Groups ExtrasAI27/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allows Cross Site Request Forgery.This issue affects BuddyPress Groups Extras: from n/a through <= 3.6.10.
AplazadaMedia (5.4)0.31%—Wpicalavailability WP Ical AvailabilityAI2/1/202517/6/2026
Missing Authorization vulnerability in WP iCal Availability WP iCal Availability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP iCal Availability: from n/a through 1.0.3.
AplazadaCrítica (9)0.47%—Cristian Lavaque S2memberAI6/12/202417/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Code Injection.This issue affects s2Member: from n/a through <= 241114.
AplazadaMedia (6.1)0.55%—Salavat CounterAI21/11/202417/6/2026
The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
AnalizadaMedia (6.1)0.50%—Lavalite26/4/202424/8/2026
Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.
ModificadaMedia (5.4)0.39%—Lava-code Lava Directory Manager14/11/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
ModificadaMedia (6.1)0.33%—Lava-code Lava Directory Manager26/10/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
ModificadaAlta (8.8)0.25%—Wpicalavailability WP Ical Availability10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions.
ModificadaAlta (7.5)0.70%—Lavalite1/8/202317/6/2026
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.