Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1956 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Criptopayer FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Criptopayer for Elementor criptopayer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Criptopayer for Elementor: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Countdowner FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Countdowner for Elementor countdowner-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Countdowner for Elementor: from n/a through <= 1.0.4. | |
| Aplazada | Media (5.4) | 0.20% | — | Merkulove Graphist FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Select Graphist for Elementor Graphist for Elementor graphist-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Select Graphist for Elementor Graphist for Elementor: from n/a through <= 1.2.10. | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Walker FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Walker for Elementor walker-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Walker for Elementor: from n/a through <= 1.1.6. | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Gmaper FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Gmaper for Elementor gmaper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gmaper for Elementor: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Sliper FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Sliper for Elementor sliper-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sliper for Elementor: from n/a through <= 1.0.10. | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Watcher FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Watcher for Elementor watcher-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Watcher for Elementor: from n/a through <= 1.0.9. | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Questionar FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Questionar for Elementor questionar-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Questionar for Elementor: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.4) | 0.24% | — | Merkulove Couponer FOR ElementorAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in merkulove Couponer for Elementor couponer-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Couponer for Elementor: from n/a through <= 1.1.7. | |
| Aplazada | Media (5.3) | 0.24% | — | Jeweltheme Master Addons FOR ElementorAI | 31/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Liton Arefin Master Addons for Elementor master-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Master Addons for Elementor: from n/a through <= 2.0.9.9.4. | |
| Analizada | Baja (1.9) | 0.28% | — | Youlai Vue3-element-admin | 31/12/2025 | 17/6/2026 | A weakness has been identified in youlaitech vue3-element-admin up to 3.4.0. This issue affects some unknown processing of the file src/views/system/notice/index.vue of the component Notice Handler. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made… | |
| Analizada | Media (6.5) | 0.15% | — | Wpdeveloper Essential Addons FOR Elementor | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite allows DOM-Based XSS.This issue affects Essential Addons for Elementor: from n/a through <= 6.5.3. | |
| Aplazada | Media (4.3) | 0.22% | — | Averta Auxin-elementsAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Averta LTD Shortcodes and extra features for Phlox theme auxin-elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.17.22. | |
| Aplazada | Media (4.3) | 0.29% | — | Premio MY Sticky ElementsAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Premio My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.3.3. | |
| Aplazada | Media (5.3) | 0.25% | — | Designthemes Homefix Elementor PortfolioAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HomeFix Elementor Portfolio: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.4) | 0.24% | — | Kitforest Better Elementor AddonsAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdive Better Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Elementor Addons: from n/a through 1.3.7. | |
| Aplazada | Media (5.4) | 0.20% | — | Codexthemes Thegem ElementorAICodexthemes Thegem WpbakeryAI | 30/12/2025 | 17/6/2026 | Vulnerability in CodexThemes TheGem (Elementor), CodexThemes TheGem (WPBakery).This issue affects TheGem (Elementor): from n/a before 5.8.1.1; TheGem (WPBakery): from n/a before 5.8.1.1. | |
| Aplazada | Media (6.5) | 0.37% | — | Jeweltheme Master Addons FOR ElementorAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Master Addons for Elementor: from n/a through 2.0.5.3. | |
| Aplazada | Media (5.9) | 0.21% | — | Voidcoders Void-visual-whmcs-elementAIWpbakery Visual ComposerAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in voidcoders WPBakery Visual Composer WHMCS Elements void-visual-whmcs-element allows DOM-Based XSS.This issue affects WPBakery Visual Composer WHMCS Elements: from n/a through <= 1.0.4.3. | |
| Aplazada | Media (6.5) | 0.17% | — | Modeltheme Addons FOR Wpbakery AND ElementorAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in modeltheme ModelTheme Addons for WPBakery and Elementor modeltheme-addons-for-wpbakery allows Stored XSS.This issue affects ModelTheme Addons for WPBakery and Elementor: from n/a through < 1.5.6. | |
| Modificada | Media (5.3) | 0.34% | — | Leap13 Premium Addons FOR Elementor | 24/12/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor allows Retrieve Embedded Sensitive Data.This issue affects Premium Addons for Elementor: from n/a through <= 4.11.53. | |
| Aplazada | Alta (7.5) | 0.38% | — | Codexthemes Thegem Elements ElementorAI | 23/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1. | |
| Aplazada | Media (6.5) | 0.16% | — | Codexthemes Thegem Theme Elements FOR ElementorAI | 23/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem Theme Elements (for Elementor) thegem-elements-elementor.This issue affects TheGem Theme Elements (for Elementor): from n/a through <= 5.10.5.1. | |
| Aplazada | Alta (7.5) | 0.29% | — | Ideabox Creations Powerpack PRO FOR ElementorAI | 23/12/2025 | 17/6/2026 | Missing Authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PowerPack Pro for Elementor: from n/a through 2.10.6. | |
| Modificada | Media (4.3) | 0.16% | — | Leap13 Premium Addons FOR Elementor | 23/12/2025 | 17/6/2026 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.11.53. This is due to missing nonce validation in the 'insert_inner_template' function. This makes it possible for unauthenticated attackers to create arbitrary Elementor templates… |