Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.8)0.17%—Lucid Vision Labs Arena SDKAI7/8/202626/8/2026
DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency…
AplazadaAlta (8.2)0.54%—Adonisjs LucidAI13/1/202617/6/2026
@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic…
AplazadaAlta (7.6)0.32%—Lucidcrew WP Forum ServerAI27/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2.
AplazadaAlta (7.1)0.12%—Lucidcrew WP Forum ServerAI27/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2.
AplazadaAlta (7.1)0.26%—N3wnormal LucidlmsAI13/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N3wNormal LucidLMS lucidlms allows Reflected XSS.This issue affects LucidLMS: from n/a through <= 1.0.5.
ModificadaCrítica (9.8)5.0%—Lucidcrew Pixie3/4/201717/6/2026
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.
ModificadaMedia (6.1)0.80%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.
ModificadaMedia (6.1)0.82%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.
ModificadaMedia (6.1)0.82%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.
ModificadaMedia (6.1)0.80%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.
ModificadaMedia (6.1)1.2%—Lucidcrew Pixie31/3/201717/6/2026
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.
ModificadaMedia (4.3)1.4%—Lucidcrew Pixie4/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.
ModificadaAlta (7.5)1.7%—Getpixie PixieLucidcrew Pixie8/12/201116/6/2026
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI.
ModificadaMedia (5)1.9%—Lucidcrew Pixie24/9/201116/6/2026
Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files.
ModificadaMedia (4.3)1.6%—Pantha Translucid22/6/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject…
ModificadaMedia (6.8)1.7%—Lucid Designs Lucid Calendar15/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5)1.3%—Lucidcms6/4/200616/6/2026
LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message.
ModificadaMedia (4.3)1.7%—Lucidcms6/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter.
ModificadaAlta (7.5)1.1%—Lucidcms4/10/200516/6/2026
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
ModificadaMedia (4.3)1.8%—Lucidcms4/10/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.