Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 13 respecto a la semana anterior
Críticas / altas1452▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.32% | — | ViteposAI | 30/9/2026 | 30/9/2026 | Custom role Privilege Escalation in Vitepos <= 3.5.0 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Devitems Hashbar Wordpress Notification BARAI | 22/9/2026 | 22/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.3. | |
| Aplazada | Media (5.9) | 0.53% | — | Vitest.dev VitestAI | 1/9/2026 | 9/9/2026 | Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:register handler on Vite's unauthenticated HMR WebSocket without validating redirect… | |
| Aplazada | Baja (1.1) | 0.90% | — | Tanstack Devtools-viteAI | 24/8/2026 | 24/8/2026 | A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools Event Bus. The manipulation of the argument packageName results in os command injection. Attacking… | |
| Aplazada | Alta (8.8) | 0.20% | — | Devitems Hashbar Wordpress Notification BARAI | 18/8/2026 | 20/8/2026 | Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0. | |
| Pendiente de análisis | Media (5.3) | 0.43% | — | Linuxfoundation VitessAI | 18/8/2026 | 18/9/2026 | Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoint() in go/vt/vttablet/tabletmanager/vreplication/vrlog.go invokes vrlogStatsHandler() without acl.CheckAccessHTTP(r, acl.DEBUGGING), unlike comparable debug endpoints. A… | |
| Aplazada | Crítica (9.4) | 0.79% | — | Vitest.dev VitestAI | 13/8/2026 | 9/9/2026 | Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or… | |
| Aplazada | Media (4.1) | 0.31% | — | ViteposAI | 10/8/2026 | 26/8/2026 | The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection. | |
| Aplazada | Alta (7.2) | 0.46% | — | ViteposAI | 10/8/2026 | 26/8/2026 | The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an Outlet Manager to reset any user's… | |
| Aplazada | Crítica (9.6) | 0.63% | — | NuxtAIVuejs Vue.jsAIVitejs ViteAI | 5/8/2026 | 8/9/2026 | Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client that can reach the Vite HMR endpoint… | |
| Pendiente de análisis | Crítica (9.8) | 0.90% | — | Vitest.dev VitestAI | 14/7/2026 | 29/7/2026 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed browser API metadata to use CDP… | |
| Analizada | Media (5.9) | 0.88% | — | Vitest.dev Vitest | 14/7/2026 | 6/8/2026 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun features such as saveTestFile and rerun could… | |
| Aplazada | Crítica (9.6) | 0.61% | — | Vitest.dev VitestAI | 14/7/2026 | 15/7/2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary JavaScript in the Vitest server origin… | |
| Analizada | Crítica (9.3) | 4.0% | — | Vitec Flamingo | 13/7/2026 | 14/8/2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the… | |
| Analizada | Crítica (9.3) | 3.3% | — | Vitec Flamingo | 13/7/2026 | 14/8/2026 | Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST… | |
| Aplazada | Alta (8.5) | 0.36% | — | Appsbd ViteposAIAppsbd Vitepos-liteAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vitepos-lite allows Blind SQL Injection.This issue affects Vitepos: from n/a through <= 3.4.2. | |
| Aplazada | Alta (7.5) | 0.42% | — | ViteposAI | 25/6/2026 | 25/6/2026 | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. | |
| Analizada | Alta (8.2) | 0.58% | — | Vitejs ViteVoidzero Vite+ | 22/6/2026 | 24/6/2026 | Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through server.fs.deny, including entries such as .env, .env.*, and… | |
| Aplazada | Alta (8.8) | 0.42% | — | ViteposAI | 22/6/2026 | 22/6/2026 | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator. | |
| Aplazada | Alta (7.5) | 0.51% | — | Launch-editorAIVitejs ViteAI | 1/6/2026 | 4/9/2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that contains special characters. This issue has… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Analizada | Alta (8.4) | 0.43% | — | Voidzero Vite+ | 23/4/2026 | 17/6/2026 | Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an absolute path to escape the `VP_HOME/package_manager/<pm>/` cache root and make… | |
| Analizada | Media (6.3) | 0.98% | — | Vitejs ViteVoidzero Vite+ | 7/4/2026 | 24/7/2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls readFile without restricting ../ segments in the URL. As a result, it is possible to bypass the server.fs.strict allow… | |
| Modificada | Alta (8.2) | 1.5% | — | Vitejs ViteVoidzero Vite+ | 7/4/2026 | 4/8/2026 | Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended. This… | |
| Modificada | Alta (8.2) | 2.6% | — | Vitejs ViteVoidzero Vite+ | 7/4/2026 | 25/8/2026 | Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine file://... with ?raw (or ?inline) to… |