Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.40% | — | Wpdeveloper Embedpress | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.8. | |
| Modificada | Media (5.3) | 0.34% | — | Wpdeveloper Embedpress | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper EmbedPress.This issue affects EmbedPress: from n/a through 3.9.11. | |
| Modificada | Alta (8.8) | 0.41% | — | Wpdeveloper Essential Blocks | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg.This issue affects Essential Blocks for Gutenberg: from n/a through 4.4.9. | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Essential Addons FOR Elementor | 7/6/2024 | 17/6/2026 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_lightbox_open_btn_icon’ parameter within the Lightbox & Modal widget in all versions up to, and including, 5.8.15 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Media (5.4) | 0.32% | — | Wpdeveloper Essential Addons FOR Elementor | 6/6/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'get_manual_calendar_events' function in all versions up to, and including, 5.9.22 due to insufficient input sanitization and output escaping.… | |
| Modificada | Media (5.4) | 0.31% | — | Wpdeveloper Embedpress | 5/6/2024 | 17/6/2026 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's EmbedPress PDF widget in all versions up to, and including, 4.0.1 due… | |
| Modificada | Media (5.4) | 0.33% | — | Wpdeveloper Essential Addons FOR Elementor | 30/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Twitter Feed component in all versions up to, and including, 5.9.21 due to insufficient input sanitization and output escaping. This makes it… | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Essential Addons FOR Elementor | 29/5/2024 | 17/6/2026 | The Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Team Member Carousel widget in all Pro versions up to, and including, 5.8.14 due to insufficient input sanitization and output… | |
| Modificada | Media (4.3) | 0.28% | — | Wpdeveloper Embedpress | 23/5/2024 | 17/6/2026 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of functionality due to insufficient authorization validation on the PDF embed block in all versions up to, and including,… | |
| Modificada | Media (5.4) | 0.47% | — | Wpdeveloper Essential Blocks | 18/5/2024 | 17/6/2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tagName’ parameter in versions up to, and including, 4.5.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (8.8) | 0.82% | — | Wpdeveloper Essential Addons FOR Elementor | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8. | |
| Modificada | Media (4.3) | 0.37% | — | Wpdeveloper Reviewx | 16/5/2024 | 17/6/2026 | The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletion of data due to a missing capability check on the reviewx_remove_guest_image function in all versions up to, and including, 1.6.27. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.44% | — | Wpdeveloper Essential Addons FOR Elementor | 14/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_ext_toc_title_tag’ parameter in versions up to, and including, 5.9.20 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Media (5.4) | 0.34% | — | Wpdeveloper Essential Addons FOR Elementor | 14/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in all versions up to,… | |
| Modificada | Media (6.1) | 0.50% | — | Wpdeveloper Essential Addons FOR Elementor | 14/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 due to insufficient… | |
| Modificada | Media (5.4) | 0.34% | — | Wpdeveloper Embedpress | 14/5/2024 | 17/6/2026 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 3.9.16 due to insufficient input sanitization and… | |
| Modificada | Media (5.4) | 0.34% | — | Wpdeveloper Essential Addons FOR Elementor | 14/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and output escaping on… | |
| Aplazada | Media (6.5) | 0.60% | — | Wpdeveloper SchedulepressAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper SchedulePress.This issue affects SchedulePress: from n/a through 5.0.8. | |
| Modificada | Alta (8.8) | 0.40% | — | Wpdeveloper Reviewx | 3/5/2024 | 17/6/2026 | Broken Access Control vulnerability in ReviewX.This issue affects ReviewX: from n/a through 1.6.21. | |
| Modificada | Media (5.4) | 0.60% | — | Wpdeveloper Essential Addons FOR Elementor | 2/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_event_text_color’ parameter in versions up to, and including, 5.9.17 due to insufficient input sanitization and output escaping. This makes… | |
| Modificada | Media (5.4) | 0.48% | — | Wpdeveloper Essential Addons FOR Elementor | 2/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the eael_team_members_image_rounded parameter in the Team Members widget in all versions up to, and including, 5.9.15 due to insufficient input… | |
| Modificada | Media (6.4) | 0.55% | — | Wpdeveloper Essential Addons FOR Elementor | 2/5/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery & Interactive Circle widgets in all versions up to, and including, 5.9.15 due to insufficient input sanitization and… | |
| Analizada | Alta (7.8) | 0.26% | — | IBM Rational Developer FOR IIBM I | 28/4/2024 | 17/6/2026 | IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges. IBM X-Force ID:… | |
| Modificada | Media (5.3) | 0.50% | — | Wpdeveloper Essential Addons FOR Elementor | 25/4/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions.… | |
| Modificada | Media (6.4) | 0.33% | — | Wpdeveloper Essential Addons FOR Elementor | 22/4/2024 | 17/6/2026 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Counter widget in all versions up to, and including, 5.8.11 due to insufficient input sanitization and output escaping on user supplied attributes such as 'title_html_tag'. This makes it possible… |