Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.94% | — | LavagueAI | 4/9/2026 | 10/9/2026 | LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt injection to execute arbitrary code on the… | |
| Aplazada | Alta (8.6) | 0.19% | — | Lavavo CD RipperAI | 22/3/2026 | 17/6/2026 | Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Activation Name field. Attackers can craft a payload with controlled buffer data, NSEH jump instructions, and SEH… | |
| Aplazada | Media (4.4) | 0.31% | — | Salavat CounterAI | 19/2/2026 | 17/6/2026 | The salavat counter Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'image_url' parameter in all versions up to, and including, 0.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and… | |
| Analizada | Alta (8.8) | 0.46% | — | Lavalite | 13/2/2026 | 17/6/2026 | LavaLite CMS 10.1.0 is vulnerable to Incorrect Access Control. An authenticated user with low-level privileges (User role) can directly access the admin backend by logging in through /admin/login. The vulnerability exists because the admin and user authentication guards share the same user provider without role-based… | |
| Aplazada | Alta (8.5) | 0.17% | — | Lavasoft Adaware WEB CompanionAI | 5/2/2026 | 17/6/2026 | Adaware Web Companion version 4.8.2078.3950 contains an unquoted service path vulnerability in the WCAssistantService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Lavasoft\Web Companion\Application\ to inject malicious… | |
| Analizada | Media (5.1) | 0.23% | — | Lavalite | 23/1/2026 | 14/7/2026 | LavaLite CMS versions up to and including 10.1.0 contain a stored cross-site scripting vulnerability in the package creation and search functionality. Authenticated users can supply crafted HTML or JavaScript in the package Name or Description fields that is stored and later rendered without proper output encoding in… | |
| Aplazada | Crítica (9) | 0.42% | — | Cristian Lavaque S2memberAI | 22/10/2025 | 29/9/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905. | |
| Aplazada | Alta (7.3) | 0.29% | — | Lavasoft WEB CompanionAI | 9/10/2025 | 17/6/2026 | Lavasoft Web Companion (also known as Ad-Aware WebCompanion) versions 8.9.0.1091 through 12.1.3.1037 installs the DCIService.exe service with an unquoted service path vulnerability. An attacker with write access to the file system could potentially execute arbitrary code with elevated privileges by placing a malicious… | |
| Analizada | Crítica (9.3) | 0.50% | — | Hliu Llava | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthorized web actions or… | |
| Analizada | Media (6.1) | 0.52% | — | Hliu Llava | 20/3/2025 | 17/6/2026 | An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft. | |
| Analizada | Alta (7.5) | 0.69% | — | Hliu Llava | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such as AWS metadata… | |
| Analizada | Alta (7.5) | 0.93% | — | Hliu Llava | 20/3/2025 | 17/6/2026 | A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component. | |
| Modificada | Alta (7.5) | 0.62% | — | Hliu Llava | 20/3/2025 | 17/6/2026 | A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessible. | |
| Aplazada | Media (5.9) | 0.29% | — | Lavacode Lava Ajax SearchAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search lava-ajax-search allows Stored XSS.This issue affects Lava Ajax Search: from n/a through <= 1.1.9. | |
| Aplazada | Alta (7.1) | 0.32% | — | Cristian Lavaque S2memberAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cristián Lávaque s2Member s2member allows Reflected XSS.This issue affects s2Member: from n/a through <= 241216. | |
| Analizada | Media (6.1) | 0.43% | — | Clavaque S2member | 18/2/2025 | 17/6/2026 | The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 241114. This makes it… | |
| Aplazada | Media (5.4) | 0.16% | — | Slava Abakumov Buddypress Groups ExtrasAI | 27/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Slava Abakumov BuddyPress Groups Extras buddypress-groups-extras allows Cross Site Request Forgery.This issue affects BuddyPress Groups Extras: from n/a through <= 3.6.10. | |
| Aplazada | Media (5.4) | 0.31% | — | Wpicalavailability WP Ical AvailabilityAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in WP iCal Availability WP iCal Availability allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP iCal Availability: from n/a through 1.0.3. | |
| Aplazada | Crítica (9) | 0.47% | — | Cristian Lavaque S2memberAI | 6/12/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Code Injection.This issue affects s2Member: from n/a through <= 241114. | |
| Aplazada | Media (6.1) | 0.55% | — | Salavat CounterAI | 21/11/2024 | 17/6/2026 | The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Media (6.1) | 0.50% | — | Lavalite | 26/4/2024 | 24/8/2026 | Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL. | |
| Modificada | Media (5.4) | 0.39% | — | Lava-code Lava Directory Manager | 14/11/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions. | |
| Modificada | Media (6.1) | 0.33% | — | Lava-code Lava Directory Manager | 26/10/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wpicalavailability WP Ical Availability | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WP iCal Availability plugin <= 1.0.3 versions. | |
| Modificada | Alta (7.5) | 0.70% | — | Lavalite | 1/8/2023 | 17/6/2026 | LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. |