Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.48% | — | B M Rafiul Alam Elementor Timeline WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in B.M. Rafiul Alam Elementor Timeline Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Timeline Widget: from n/a through 2.2. | |
| Aplazada | Media (5.3) | 0.47% | — | Inisev Enhanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in cl272 Enhanced Text Widget enhanced-text-widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through <= 1.6.3. | |
| Aplazada | Media (5.3) | 0.44% | — | MAX Chirkov Advanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Max Chirkov Advanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced Text Widget : from n/a through 2.1.2. | |
| Aplazada | Media (4.3) | 0.50% | — | Inisev Enhanced Text WidgetAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Clever Widgets Enhanced Text Widget allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Text Widget: from n/a through 1.5.8. | |
| Aplazada | Alta (7.1) | 0.17% | — | Paloma WidgetAI | 6/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Paloma Paloma Widget postman-widget allows Cross Site Request Forgery.This issue affects Paloma Widget: from n/a through <= 1.14. | |
| Modificada | Media (5.4) | 0.29% | — | Codeless Cowidgets Elementor Addons | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons cowidgets-elementor-addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through <= 1.2.0. | |
| Modificada | Crítica (9.8) | 0.66% | — | Coolplugins Cryptocurrency Widgets FOR Elementor | 30/11/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through <=… | |
| Aplazada | Alta (7.1) | 0.17% | — | Wpwox Footer Flyout WidgetAI | 28/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpwox Footer Flyout Widget footer-flyout-widget allows Stored XSS.This issue affects Footer Flyout Widget: from n/a through <= 1.1. | |
| Aplazada | Crítica (9.9) | 44% | 💥 PoC | Widget OptionsAI | 28/11/2024 | 17/6/2026 | The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due to the plugin allowing users to supply input that will be… | |
| Analizada | Media (6.1) | 0.59% | — | Hedge3 Crypto AND Defi Widgets | 21/11/2024 | 17/6/2026 | The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.6. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (4.3) | 0.52% | — | Stratum Elementor WidgetsAI | 21/11/2024 | 17/6/2026 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.4 in includes/templates/content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private,… | |
| Aplazada | Alta (7.1) | 0.27% | — | Weather-atlas Weather Atlas WidgetAI | 20/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weather Atlas Weather Atlas Widget weather-atlas allows Reflected XSS.This issue affects Weather Atlas Widget: from n/a through <= 3.0.3. | |
| Modificada | Alta (8.8) | 0.20% | — | Vivwebsolutions Dynamic Widgets | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kalmang Dynamic Widgets dynamic-widgets.This issue affects Dynamic Widgets: from n/a through <= 1.6.4. | |
| Aplazada | Media (6.5) | 0.29% | — | Philspectrum Icon Widget With LinksAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in philspectrum Icon Widget icon-widget-with-links allows DOM-Based XSS.This issue affects Icon Widget: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.32% | — | Lilaeamedia Intelliwidget ElementsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lilaeamedia IntelliWidget Elements intelliwidget-elements allows DOM-Based XSS.This issue affects IntelliWidget Elements: from n/a through <= 2.2.7. | |
| Aplazada | Media (6.5) | 0.32% | — | Codstack WP Automatic WidgetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codstack wp_automatic_widget wp-automatic-widget allows DOM-Based XSS.This issue affects wp_automatic_widget: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Duogeek Custom Dashboard WidgetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DuoGeek Custom Dashboard Widget create-custom-dashboard-widget allows Stored XSS.This issue affects Custom Dashboard Widget: from n/a through <= 1.0.0. | |
| Aplazada | Media (6.5) | 0.38% | — | Salehattari Best Bootstrap Widgets FOR ElementorAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salehattari best bootstrap widgets for elementor best-bootstrap-widgets-for-elementor allows DOM-Based XSS.This issue affects best bootstrap widgets for elementor: from n/a through <= 1.0. | |
| Aplazada | Media (6.5) | 0.37% | — | Zachsilberstein RLM Elementor Widgets PackAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zachsilberstein RLM Elementor Widgets Pack rlm-elementor-widgets-pack allows DOM-Based XSS.This issue affects RLM Elementor Widgets Pack: from n/a through <= 1.3.1. | |
| Aplazada | Media (6.5) | 0.36% | — | Alleythemes Alley Elementor WidgetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alleythemes Alley Elementor Widget alley-elementor-widget allows DOM-Based XSS.This issue affects Alley Elementor Widget: from n/a through <= 1.0.7. | |
| Analizada | Media (5.4) | 0.30% | — | Crocoblock Jetwidgets FOR Elementor | 12/11/2024 | 17/6/2026 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.0.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above,… | |
| Analizada | Media (5.9) | 0.31% | — | RSS Feed Widget Project RSS Feed Widget | 12/11/2024 | 17/6/2026 | The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Media (4.8) | 0.31% | — | Fahadmahmood RSS Feed Widget | 12/11/2024 | 17/6/2026 | The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
| Modificada | Media (5.4) | 0.27% | — | Coolplugins WEB Stories Widgets FOR Elementor | 11/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cool Plugins Web Stories Widgets For Elementor shortcodes-for-amp-web-stories-and-elementor-widget allows Stored XSS.This issue affects Web Stories Widgets For Elementor: from n/a through <= 1.1. | |
| Modificada | Media (5.4) | 0.25% | — | Kendysond Selar.co Widget | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kendysond Selar.co Widget selar-co-widget allows DOM-Based XSS.This issue affects Selar.co Widget: from n/a through <= 1.2. |