Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
206 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.45% | — | TZ Weekly Radio ScheduleAI | 18/9/2026 | 18/9/2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | |
| Aplazada | Alta (8.6) | 0.45% | — | TZ Weekly Radio ScheduleAI | 18/9/2026 | 18/9/2026 | The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before using it to build a SQL query on an AJAX action available to unauthenticated users, allowing unauthenticated attackers to perform SQL injection attacks and extract sensitive data from the database. | |
| Aplazada | Alta (7.1) | 0.25% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | |
| Aplazada | Alta (8.7) | 0.46% | — | Qwen-agentAIGradioAI | 28/8/2026 | 23/9/2026 | Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser that fails to restrict file access to intended directories. Attackers can supply absolute file paths to the unauthenticated Gradio interface to read arbitrary files accessible by the server process. | |
| Aplazada | Alta (8.7) | 0.35% | — | Alibaba Qwen-agentAIGradioAI | 28/8/2026 | 23/9/2026 | Qwen-Agent through 0.0.34 contains a server-side request forgery vulnerability in the document parsing path that treats caller-supplied paths as URLs without scheme restriction or host validation. Attackers can reach the unauthenticated Gradio interface to make the server issue HTTP requests to arbitrary internal… | |
| Aplazada | Alta (7.8) | 0.21% | — | Chirpmyradio ChirpAI | 23/8/2026 | 9/9/2026 | chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py. | |
| Aplazada | Media (5.3) | 0.29% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | |
| Aplazada | Media (4.9) | 0.44% | — | GradioAI | 8/7/2026 | 10/7/2026 | Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to redirect users to arbitrary URLs or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the file_fetch() function in the /gradio_api/file= endpoint. Attackers can craft a malicious… | |
| Analizada | Alta (8.7) | 0.93% | — | Gradio Project Gradio | 1/7/2026 | 14/7/2026 | Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path… | |
| Analizada | Baja (1.1) | 0.11% | — | Gradio Project Gradio | 4/6/2026 | 22/7/2026 | A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of weak hash. The attack must be initiated from a local position. The attack is considered to have high complexity. It is… | |
| Analizada | Alta (7.6) | 0.47% | — | Gradio Project Gradio | 27/5/2026 | 14/7/2026 | Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across all users in the reverse proxy endpoint. Attackers controlling any HF Space can return a parent-domain cookie that the… | |
| Analizada | Crítica (9.9) | 0.37% | — | Sonicverse Radio Audio Streaming Stack | 9/4/2026 | 17/6/2026 | Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. The Sonicverse Radio Audio Streaming Stack dashboard contains a Server-Side Request Forgery (SSRF) vulnerability in its API client (apps/dashboard/lib/api.ts). Installations created using the provided install.sh script (including the one‑liner… | |
| Aplazada | Media (5.4) | 0.22% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11. | |
| Analizada | Media (6.9) | 0.19% | — | Raimersoft Rarmaradio | 22/3/2026 | 17/6/2026 | RarmaRadio 2.72.3 contains a buffer overflow vulnerability in the Server field of the Network settings that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a malicious payload exceeding 4000 bytes into the Server field via the Settings menu to trigger an… | |
| Analizada | Media (6.9) | 0.18% | — | Raimersoft Rarmaradio | 22/3/2026 | 17/6/2026 | RarmaRadio 2.72.3 contains a denial of service vulnerability in the Username field that allows local attackers to crash the application by submitting excessively long input. Attackers can paste a buffer of 5000 bytes into the Username field via Settings > Network to trigger an application crash. | |
| Analizada | Alta (8.6) | 0.35% | — | Gradio Project Gradio | 27/2/2026 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitrary HTTP requests from a victim's server by hosting a malicious Gradio Space. When a victim application uses `gr.load()` to load… | |
| Analizada | Media (4.7) | 0.29% | — | Gradio Project Gradio | 27/2/2026 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target() function in Gradio's OAuth flow accepts an unvalidated _target_url query parameter, allowing redirection to arbitrary external URLs. This affects the /logout and /login/callback endpoints on Gradio… | |
| Analizada | Alta (7.5) | 2.5% | — | Gradio Project Gradio | 27/2/2026 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated attackers to read arbitrary files from the file system. Python 3.13+ changed the definition of… | |
| Analizada | Media (5.9) | 0.39% | — | Gradio Project Gradio | 27/2/2026 | 17/6/2026 | Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version 6.6.0, Gradio applications running outside of Hugging Face Spaces automatically enable "mocked" OAuth routes when OAuth components (e.g. `gr.LoginButton`) are used. When a user visits… | |
| Analizada | Media (5.1) | 0.29% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user profile update workflow (user_settings.php submitting to admin/update_user.php). Authenticated users can store malicious HTML/JavaScript in fields such as Firstname, lastname, email, and image_url, which are later rendered… | |
| Analizada | Media (5.1) | 0.32% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a stored cross-site scripting vulnerability in the user registration workflow (index.php submitting to admin/user_action.php). User-supplied fields such as Firstname, lastname, and email are stored in the backend database without adequate output encoding and are later rendered… | |
| Analizada | Media (5.1) | 0.33% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in radiomobile_front.php via the stationid query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value into a hidden input value field, allowing attacker-supplied… | |
| Analizada | Media (5.1) | 0.28% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in admin/log.php via the search query parameter. When an authenticated administrator views a crafted URL, the application embeds the unsanitized parameter value directly into an HTML input value attribute, allowing attacker-supplied… | |
| Analizada | Media (5.1) | 0.36% | — | Radioinorr Svxportal | 20/2/2026 | 14/7/2026 | SVXportal version 2.5 and prior contain a reflected cross-site scripting vulnerability in log.php via the search query parameter. The application embeds the unsanitized parameter value directly into an HTML input value attribute, allowing an unauthenticated remote attacker to inject and execute arbitrary JavaScript in… | |
| Analizada | Media (6.7) | 0.24% | — | Raimersoft Tapinradio | 7/2/2026 | 17/6/2026 | TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality. |