Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.36% | — | Ultimatemember Ultimate Member | 18/1/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.9.1 through different error messages in the responses. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 0.53% | — | Ultimatemember Ultimate Member | 18/1/2025 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the search parameter in all versions up to, and including, 2.9.1 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Media (6.5) | 0.23% | — | Wpfreeware WPF Ultimate CarouselAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpfreeware WpF Ultimate Carousel wpf-ultimate-carousel allows Stored XSS.This issue affects WpF Ultimate Carousel: from n/a through <= 1.0.11. | |
| Aplazada | Alta (7.5) | 0.78% | 💥 PoC | Wpswings Ultimate Gift Cards FOR WoocommerceAI | 8/1/2025 | 17/6/2026 | The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Coupons. Offer Gift Certificates, Schedule Gift Cards, and Use Advance Coupons With Personalized Templates plugin for WordPress is vulnerable to unauthorized modification of data due to a missing… | |
| Analizada | Alta (8.8) | 0.75% | — | Wpextended Ultimate Wordpress Toolkit | 8/1/2025 | 17/6/2026 | The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the 'wpext_handle_snippet_update' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute… | |
| Aplazada | Alta (7.6) | 0.50% | — | Wpindeed Ultimate Learning PROAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpIndeed Ultimate Learning Pro allows SQL Injection.This issue affects Ultimate Learning Pro: from n/a through 3.9. | |
| Aplazada | Media (6.5) | 0.21% | — | Themebon Ultimate Image Hover EffectsAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themebon Ultimate Image Hover Effects ultimate-image-hover-effects allows DOM-Based XSS.This issue affects Ultimate Image Hover Effects: from n/a through <= 1.1.2. | |
| Aplazada | Media (6.5) | 0.56% | — | Essentialplugin Hero Banner UltimateAI | 7/1/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Essential Plugin Hero Banner Ultimate hero-banner-ultimate allows PHP Local File Inclusion.This issue affects Hero Banner Ultimate: from n/a through <= 1.4.4. | |
| Aplazada | Crítica (9.1) | 1.9% | 💥 PoC | Smackcoders INC WP Ultimate ExporterAI | 7/1/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders Inc., WP Ultimate Exporter wp-ultimate-exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through <= 2.9.1. | |
| Aplazada | Media (4.3) | 0.19% | — | Ultimate AuctionAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nitesh Ultimate Auction ultimate-auction allows Cross Site Request Forgery.This issue affects Ultimate Auction : from n/a through <= 4.2.5. | |
| Aplazada | Alta (7.5) | 0.52% | — | Themefic Ultimate Addons FOR Contact Form 7AI | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Themefic Ultimate Addons for Contact Form 7 ultimate-addons-for-contact-form-7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Addons for Contact Form 7: from n/a through <= 3.2.6. | |
| Analizada | Media (6.8) | 0.32% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in IObit Advanced SystemCare Utimate up to 17.0.0. This affects the function 0x8001E040 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit… | |
| Analizada | Media (6.8) | 0.38% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been rated as problematic. Affected by this issue is the function 0x8001E024 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. The attack needs to be approached… | |
| Analizada | Media (6.8) | 0.46% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been declared as problematic. Affected by this vulnerability is the function 0x8001E018 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. It is possible to launch… | |
| Analizada | Media (6.8) | 0.46% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0. It has been classified as problematic. Affected is the function 0x8001E004 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The… | |
| Analizada | Media (6.8) | 0.46% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability was found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This issue affects the function 0x8001E01C in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. Local access is required to approach this… | |
| Analizada | Media (6.8) | 0.38% | — | Iobit Advanced Systemcare Ultimate | 16/12/2024 | 17/6/2026 | A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has to be approached… | |
| Aplazada | Crítica (9.9) | 0.66% | — | Suiteplugins Video AND Photo Gallery FOR Ultimate MemberAI | 16/12/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in SuitePlugins Video & Photo Gallery for Ultimate Member gallery-for-ultimate-member allows Upload a Web Shell to a Web Server.This issue affects Video & Photo Gallery for Ultimate Member: from n/a through <= 1.1.0. | |
| Modificada | Crítica (9.8) | 0.71% | — | Ultimatemember Forumwp | 16/12/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Ultimate Member ForumWP forumwp allows Object Injection.This issue affects ForumWP: from n/a through <= 2.1.0. | |
| Aplazada | Alta (7.1) | 0.41% | — | Cmorillas1 Ultimate Shortcodes CreatorAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmorillas1 Shortcodes Blocks Creator Ultimate ultimate-shortcodes-creator allows Reflected XSS.This issue affects Shortcodes Blocks Creator Ultimate: from n/a through <= 2.2.0. | |
| Analizada | Media (5.4) | 0.29% | — | Dotcamp Ultimate Blocks | 13/12/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Aplazada | Media (6.1) | 0.42% | — | Video Photo Gallery FOR Ultimate MemberAI | 12/12/2024 | 17/6/2026 | The Video & Photo Gallery for Ultimate Member plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.1) | 0.39% | — | Ultimate Endpoints With Rest APIAI | 12/12/2024 | 17/6/2026 | The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Alta (8.8) | 0.55% | — | Ultimatemember Jobboardwp | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in JobBoardWP JobBoardWP – Job Board Listings and Submissions allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobBoardWP – Job Board Listings and Submissions: from n/a through 1.2.2. | |
| Analizada | Media (6.1) | 0.31% | — | Cmorillas1 Shortcodes Blocks Creator Ultimate | 7/12/2024 | 17/6/2026 | The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… |