Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Visualmodo Borderless | 30/1/2025 | 17/6/2026 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.6.0 via the 'write_config' function. This is due to a lack of sanitization on an imported JSON file. This makes it possible for… | |
| Modificada | Media (4.3) | 0.38% | — | Visualmodo Borderless | 30/1/2025 | 17/6/2026 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_zipped_font' function in all versions up to, and including, 1.5.9. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.1) | 0.23% | — | WP Busters Passwordless WPAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Busters Passwordless WP – Login with your glance or fingerprint passwordless-wp allows Reflected XSS.This issue affects Passwordless WP – Login with your glance or fingerprint: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Alessandro Benoit WpdevtoolAI | 23/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alessandro Benoit WpDevTool wpdevtool allows Reflected XSS.This issue affects WpDevTool: from n/a through <= 0.1.1. | |
| Analizada | Crítica (9) | 0.76% | — | Namelessmc Nameless | 13/1/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually… | |
| Analizada | Media (6.3) | 0.28% | — | Namelessmc Nameless | 13/1/2025 | 17/6/2026 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated once a staffer visits the user's profile on staff panel. As a result an… | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Sslplugins SSL Wireless SMS NotificationAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows SQL Injection.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.5.0. | |
| Aplazada | Media (5.3) | 0.39% | — | Cocart Headless EcommerceAI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in CoCart Headless CoCart – Headless ecommerce cart-rest-api-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CoCart – Headless ecommerce: from n/a through <= 3.11.2. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sslplugins SSL Wireless SMS NotificationAI | 31/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in sslplugins SSL Wireless SMS Notification ssl-wireless-sms-notification allows Privilege Escalation.This issue affects SSL Wireless SMS Notification: from n/a through <= 3.6.0. | |
| Aplazada | Alta (8.1) | 0.42% | — | Sierrawireless AirvantageAI | 21/12/2024 | 17/6/2026 | The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage Management Service on the devices or registered the device. This could enable an attacker to configure, manage, and execute AT commands… | |
| Modificada | Media (5.4) | 0.27% | — | Visualmodo Borderless | 6/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless borderless allows Cross-Site Scripting (XSS).This issue affects Borderless: from n/a through <= 1.5.8. | |
| Modificada | Media (5.4) | 0.29% | — | Codeless Cowidgets Elementor Addons | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons cowidgets-elementor-addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through <= 1.2.0. | |
| Analizada | Media (6.5) | 0.33% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 7832 With Multiplatform FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Conference Phone 8832 With Multiplatform Firmware+30 | 18/11/2024 | 17/6/2026 | Multiple vulnerabilities in the Cisco Discovery Protocol and Link Layer Discovery Protocol (LLDP) implementations for Cisco IP Phone Series 68xx/78xx/88xx could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP phone. These vulnerabilities are due to… | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Proset Wireless WifiAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path element in some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.28% | — | Intel Proset Wireless WifiAI | 13/11/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Aplazada | Media (4.6) | 0.18% | — | Intel Proset Wireless WifiAI | 13/11/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Media (6.8) | 0.24% | — | Intel KillerIntel Proset/wireless Wifi | 13/11/2024 | 17/6/2026 | Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi wireless products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access. | |
| Analizada | Media (4.6) | 0.18% | — | Intel KillerIntel Proset/wireless Wifi | 13/11/2024 | 17/6/2026 | Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before version 23.40 may allow a privileged user to potentially enable information disclosure via local access. | |
| Aplazada | Media (6.8) | 0.30% | — | Intel Wireless BluetoothAI | 13/11/2024 | 17/6/2026 | Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Analizada | Media (6.8) | 0.24% | — | Intel KillerIntel Proset/wireless Wifi | 13/11/2024 | 17/6/2026 | Improper input validation in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi products before version 23.40 may allow an unauthenticated user to enable denial of service via adjacent access. | |
| Modificada | Media (5.4) | 0.26% | — | Sharethepractice Christian Science Bible Lesson Subjects | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gabriel Serafini Christian Science Bible Lesson Subjects christian-science-bible-lesson-subjects allows DOM-Based XSS.This issue affects Christian Science Bible Lesson Subjects: from n/a through <= 2.0. | |
| Aplazada | Alta (8.8) | 0.56% | — | Cypress Cyw43455AIBroadcom Wireless Combo ChipsAI | 11/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips such as CYW43455, when a 2021-01-26 Bluetooth firmware update is not present, allow a Bluetooth outage via a "Spectra" attack. | |
| Aplazada | Media (5.5) | 0.39% | — | Cypress Wireless Combo ChipsAIBroadcom Wireless Combo ChipsAI | 10/11/2024 | 17/6/2026 | Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack. |