Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

1809 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.3)0.20%—Pixelite Events ManagerAI5/10/20265/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Pixelite Events Manager events-manager allows Retrieve Embedded Sensitive Data.This issue affects Events Manager: from n/a through 7.4.5.
RecibidaMedia (6.5)0.16%—Wpchill Final Tiles Grid Gallery LiteAI5/10/20265/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Chill Image Photo Gallery Final Tiles Grid final-tiles-grid-gallery-lite allows Stored XSS.This issue affects Image Photo Gallery Final Tiles Grid: from n/a through 3.6.13.
RecibidaBaja (2.9)0.40%—Linlinjava LitemallAI5/10/20265/10/2026
A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts.…
RecibidaAlta (7.2)0.24%—TransliteratorAI3/10/20263/10/2026
The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible…
RecibidaAlta (8.6)0.27%—Saveto Wishlist LiteAI3/10/20263/10/2026
The SaveTo Wishlist Lite WordPress plugin before 1.1.5 does not sanitise and escape parameters before using them in the ORDER BY clause of a SQL query, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
RecibidaMedia (6.4)0.19%—Ultrasaddons Ultra Addons LiteAI3/10/20263/10/2026
The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
RecibidaMedia (5.4)0.08%—Litespeedtech OpenlitespeedAI2/10/20265/10/2026
OpenLiteSpeed before 1.9.3 contains a local privilege escalation vulnerability in admin/misc/lsup.sh that runs unverified update packages from a nobody-writable directory as root. Attackers controlling the nobody web process can replace the package in /usr/local/lsws/autoupdate/ before extraction, so its install.sh…
Pendiente de análisisMedia (6.5)0.27%—Redhat Satellite KatelloAI1/10/20262/10/2026
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take…
Pendiente de análisisAlta (7.5)0.38%—Redhat ForemanAIRedhat SatelliteAI1/10/20262/10/2026
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a…
AplazadaMedia (6.5)0.13%—Wpmet Elementskit LiteAI1/10/20261/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
AplazadaMedia (6.5)0.13%—Wpmet Elementskit LiteAI1/10/20261/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpmet ElementsKit Elementor addons Lite elementskit-lite allows Stored XSS.This issue affects ElementsKit Elementor addons Lite: from n/a through 4.0.6.
AplazadaMedia (6.5)0.20%—Wpfusion WP Fusion LiteAI1/10/20261/10/2026
The WP Fusion Lite WordPress plugin before 3.48.0 does not require authentication on a settings handler that runs during admin initialization, allowing unauthenticated users to overwrite the site's CRM integration endpoint and credentials, after which synced user data is delivered to an attacker-chosen host.
AplazadaMedia (5.4)0.14%—WP Fusion LiteAI1/10/20261/10/2026
The WP Fusion Lite WordPress plugin before 3.48.0 does not perform a capability check on two of its admin AJAX handlers, allowing any authenticated subscriber to read other users' email addresses and to trigger a cross-user CRM re-sync.
Pendiente de análisisCrítica (9.4)0.26%—Litespeed WEB ServerAI30/9/202630/9/2026
LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "corner case."
AplazadaMedia (6.5)0.17%—Cool Formkit LiteAI30/9/202630/9/2026
Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.
AplazadaMedia (6.5)0.28%—MCP Content Manager LiteAI30/9/202630/9/2026
Subscriber Broken Access Control in MCP Content Manager Lite <= 1.1.0 versions.
AplazadaAlta (7.1)0.18%—WOO Commerce Product Table LiteAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in WooCommerce Product Table Lite <= 5.6.7 versions.
AplazadaAlta (7.5)0.29%—Gravityexport LiteAI30/9/202630/9/2026
Unauthenticated Broken Access Control in GravityExport Lite for Gravity Forms <= 2.7.2 versions.
AplazadaMedia (5.9)0.19%—Supreme Modules LiteAI30/9/202630/9/2026
Author Cross Site Scripting (XSS) in Supreme Modules Lite <= 2.5.63 versions.
AplazadaAlta (7.2)0.25%—Frontend Post Submission Manager LiteAI30/9/202630/9/2026
The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink) in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping. This makes…
Pendiente de análisisAlta (8.1)0.20%—JupyterlabAIJupyter NotebookAIJupyterlite CoreAI29/9/20262/10/2026
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled…
Pendiente de análisisMedia (6.8)0.26%—JupyterlabAIJupyterlite CoreAI29/9/202629/9/2026
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid…
Pendiente de análisisAlta (7.6)0.27%—LitellmAI28/9/202630/9/2026
LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured identity provider to authenticate as any existing user by exploiting an email-based fallback lookup in the JWT authentication flow without verifying the email_verified claim. Attackers can present a…
AplazadaMedia (6.5)0.18%—Wpforms LiteAI28/9/202628/9/2026
The WPForms Lite WordPress plugin from 1.5.0.1 to 2.0.2 does not remove shortcode delimiters from submitted field values before writing them back into the rendered form, allowing unauthenticated users to execute arbitrary shortcodes registered on the site and read the details of attachments belonging to non-public…
Pendiente de análisisAlta (8.7)0.27%—LitellmAI25/9/20261/10/2026
BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_semantic_cache_tenant_scope() and _get_metadata_variable_name(). Attackers holding…