Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.17% | — | Lucid Vision Labs Arena SDKAI | 7/8/2026 | 26/8/2026 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by placing a malicious DLL in a user-controlled directory listed in the PATH environment variable, which the SDK traverses when a required dependency… | |
| Aplazada | Alta (8.2) | 0.54% | — | Adonisjs LucidAI | 13/1/2026 | 17/6/2026 | @adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic… | |
| Aplazada | Alta (7.6) | 0.32% | — | Lucidcrew WP Forum ServerAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in lucidcrew WP Forum Server forum-server allows SQL Injection.This issue affects WP Forum Server: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.1) | 0.12% | — | Lucidcrew WP Forum ServerAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: from n/a through <= 1.8.2. | |
| Aplazada | Alta (7.1) | 0.26% | — | N3wnormal LucidlmsAI | 13/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N3wNormal LucidLMS lucidlms allows Reflected XSS.This issue affects LucidLMS: from n/a through <= 1.0.5. | |
| Modificada | Crítica (9.8) | 5.0% | — | Lucidcrew Pixie | 3/4/2017 | 17/6/2026 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack. | |
| Modificada | Media (6.1) | 0.82% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | |
| Modificada | Media (6.1) | 0.80% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack. | |
| Modificada | Media (6.1) | 1.2% | — | Lucidcrew Pixie | 31/3/2017 | 17/6/2026 | Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack. | |
| Modificada | Media (4.3) | 1.4% | — | Lucidcrew Pixie | 4/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/. | |
| Modificada | Alta (7.5) | 1.7% | — | Getpixie PixieLucidcrew Pixie | 8/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL commands via the (1) pixie_user parameter and (2) Referer HTTP header in a request to the default URI. | |
| Modificada | Media (5) | 1.9% | — | Lucidcrew Pixie | 24/9/2011 | 16/6/2026 | Pixie 1.04 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/modules/static.php and certain other files. | |
| Modificada | Media (4.3) | 1.6% | — | Pantha Translucid | 22/6/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in transLucid 1.75 allow remote attackers to inject arbitrary web script or HTML via the (a) NodeID and (b) action parameters to the default URI, and the (c) NodeID parameter to the default URI for the admin section; and allow remote authenticated users to inject… | |
| Modificada | Media (6.8) | 1.7% | — | Lucid Designs Lucid Calendar | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cal.PHP3 in Chris Lea Lucid Calendar 0.22 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 1.3% | — | Lucidcms | 6/4/2006 | 16/6/2026 | LucidCMS 2.0.0 RC4 allows remote attackers to obtain sensitive information via a direct request to /lucid_phplib/translator.php, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.7% | — | Lucidcms | 6/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in LucidCMS 2.0.0 RC4 allows remote attackers to inject arbitrary web script or HTML via the command parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Lucidcms | 4/10/2005 | 16/6/2026 | SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field. | |
| Modificada | Media (4.3) | 1.8% | — | Lucidcms | 4/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string. |