Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1071 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.93% | — | Codeless Cowidgets Elementor Addons | 6/6/2024 | 17/6/2026 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the… | |
| Modificada | Media (5.4) | 0.24% | — | Codeless Cowidgets - Elementor | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1. | |
| Modificada | Media (5.4) | 0.35% | — | Codeless Cowidgets Elementor Addons | 4/6/2024 | 17/6/2026 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (5.6) | 0.11% | — | Hypr PasswordlessAI | 21/5/2024 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1. | |
| Aplazada | Media (5.3) | 0.51% | — | Imran Sayed Headless CMSAI | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3. | |
| Modificada | Media (5.4) | 0.26% | — | Visualmodo Borderless | 17/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless borderless allows DOM-Based XSS.This issue affects Borderless: from n/a through <= 1.7.3. | |
| Aplazada | Media (5.5) | 0.18% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (4.7) | 0.36% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (4.4) | 0.22% | — | Intel Wireless BluetoothAI | 16/5/2024 | 17/6/2026 | Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access. | |
| Aplazada | Media (4.3) | 0.22% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Alta (8.2) | 0.34% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (4.3) | 0.43% | — | Intel Proset Wireless WifiAI | 16/5/2024 | 17/6/2026 | Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (5.5) | 0.49% | — | Paperless-ngxAI | 15/5/2024 | 17/6/2026 | Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue. | |
| Modificada | Media (5.4) | 0.41% | — | Visualmodo Borderless | 14/5/2024 | 17/6/2026 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Alta (8.6) | 0.63% | — | Greenwoodsoftware LessDebian LinuxNetapp Bootstrap OSNetapp HCI Storage Nodes+1 | 13/4/2024 | 17/6/2026 | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment… | |
| Modificada | Alta (7.1) | 0.41% | — | UDX Wp-stateless | 6/4/2024 | 17/6/2026 | The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update… | |
| Aplazada | Media (4.3) | 0.25% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request. | |
| Aplazada | Alta (7.1) | 0.69% | — | Elecom Wireless LAN RouterAI | 4/4/2024 | 17/6/2026 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product. | |
| Analizada | Alta (7.4) | 0.29% | — | Cisco Wireless LAN Controller SoftwareCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed… | |
| Analizada | Alta (8.6) | 0.63% | — | Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software | 27/3/2024 | 17/6/2026 | A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this… | |
| Aplazada | Media (6.5) | 0.33% | — | Cozmoslabs Passwordless LoginAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2. | |
| Modificada | Alta (7.5) | 0.94% | — | Intel Inet Wireless DaemonFedoraproject Fedora | 3/3/2024 | 17/6/2026 | p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails. | |
| Modificada | Alta (7.5) | 1.1% | — | Intel Inet Wireless Daemon | 22/2/2024 | 17/6/2026 | The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key. | |
| Modificada | Alta (7.8) | 1.1% | — | Greenwoodsoftware Less | 19/2/2024 | 17/6/2026 | close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE. | |
| Aplazada | Baja (2.3) | 0.39% | — | Intel Proset WirelessAIIntel Killer WI FIAI | 14/2/2024 | 17/6/2026 | Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access. |