Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 303 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.13% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.9) | 0.24% | — | Havelsan Liman Render EngineAI | 24/9/2026 | 24/9/2026 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM). This issue affects Liman Render Engine: from 1.0 before 1.2-75. | |
| Aplazada | Media (5.3) | 0.26% | — | Havelsan Liman MYSAI | 24/9/2026 | 24/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124. | |
| Aplazada | Crítica (9.1) | 1.4% | — | LimanAI | 27/8/2026 | 9/9/2026 | Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address` parameter is embedded directly into a shell… | |
| Aplazada | Alta (8.8) | 0.42% | — | Havelsan INC Liman MYSAI | 4/8/2026 | 26/8/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |
| Aplazada | Alta (8.8) | 0.42% | — | Havelsan INC Liman MYSAI | 4/8/2026 | 26/8/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1. | |
| Aplazada | Alta (8.2) | 0.20% | — | Linuxfoundation LimaAI | 10/7/2026 | 14/7/2026 | Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima running with the qemu driver, an arbitrary user in the VM could access /run/lima-guestagent.sock when the guest agent is enabled, which could result in running arbitrary commands with root… | |
| Aplazada | Media (4.8) | 0.23% | — | Limatek System INC Limrad NACAI | 8/7/2026 | 20/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Limatek System Inc. LimRAD NAC allows Stored XSS. This issue affects LimRAD NAC: before 5.5.7.3.9. | |
| Aplazada | Alta (8.8) | 0.52% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Alta (8.1) | 0.25% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Alta (8.3) | 0.35% | — | Havelsan Liman MYSAI | 7/7/2026 | 7/7/2026 | Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Limatek System INC Limrad NACAI | 11/6/2026 | 17/6/2026 | Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9. | |
| Modificada | Media (5.1) | 0.19% | — | Salihciftci Liman | 29/1/2026 | 17/6/2026 | Liman 0.7 contains a cross-site request forgery vulnerability that allows attackers to manipulate user account settings without proper request validation. Attackers can craft malicious HTML forms to change user passwords or modify account information by tricking logged-in users into submitting unauthorized requests. | |
| Aplazada | Media (5.3) | 0.33% | — | Andrew Lima Sitewide Notice WPAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Andrew Lima Sitewide Notice WP sitewide-notice-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sitewide Notice WP: from n/a through <= 2.4.1. | |
| Aplazada | Media (5.4) | 0.32% | — | Climaxthemes Kata PlusAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Climax Themes Kata Plus kata-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Kata Plus: from n/a through <= 1.5.3. | |
| Aplazada | Crítica (9.8) | 0.62% | — | Climaxthemes Kata PlusAI | 17/4/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Climax Themes Kata Plus kata-plus allows Object Injection.This issue affects Kata Plus: from n/a through <= 1.5.3. | |
| Aplazada | Media (4.8) | 0.18% | — | Havelsan Liman MYSAI | 18/2/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in HAVELSAN Liman MYS allows Cross-Site Flashing. This issue affects Liman MYS: before 2.1.1 - 1010. | |
| Aplazada | Media (6.4) | 0.36% | — | Climaxthemes Kata PlusAI | 29/10/2024 | 17/6/2026 | The Kata Plus – Addons for Elementor – Widgets, Extensions and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.26% | — | Climaxthemes Kata Plus | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Climax Themes Kata Plus kata-plus allows DOM-Based XSS.This issue affects Kata Plus: from n/a through <= 1.4.7. | |
| Modificada | Media (6.1) | 1.0% | — | Ajaydsouza Connections ReloadedArchimidismertzanos Atlast BusinessArchimidismertzanos Fashionable StoreArchimidismertzanos Nothing Personal+42 | 4/9/2023 | 17/6/2026 | All of the above Aapna WordPress theme through 1.3, Anand WordPress theme through 1.2, Anfaust WordPress theme through 1.1, Arendelle WordPress theme before 1.1.13, Atlast Business WordPress theme through 1.5.8.5, Bazaar Lite WordPress theme before 1.8.6, Brain Power WordPress theme through 1.2, BunnyPressLite… | |
| Modificada | Baja (2.5) | 0.27% | — | Linuxfoundation Lima | 30/5/2023 | 17/6/2026 | Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to version 0.16.0, a virtual machine instance with a malicious disk image could read a single file on the host filesystem, even when no filesystem is mounted from the host. The official templates of Lima and the well-known third… | |
| Modificada | Alta (8.8) | 1.8% | — | Liman Port MYS | 1/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462. | |
| Modificada | Media (6.5) | 0.75% | — | Siemens Climatix Pol909 Firmware | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The handling of log files in the web application of affected devices contains an information disclosure vulnerability which could allow logged in users to access sensitive… | |
| Modificada | Media (6.1) | 0.56% | — | Siemens Climatix Pol909 Firmware | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The User Management page of affected devices is vulnerable to cross-site scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could… | |
| Modificada | Media (6.1) | 0.56% | — | Siemens Climatix Pol909 Firmware | 8/3/2022 | 17/6/2026 | A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.44), Climatix POL909 (AWM module) (All versions < V11.36). The Group Management page of affected devices is vulnerable to cross-site scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which… |