Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1071 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.93%—Codeless Cowidgets Elementor Addons6/6/202417/6/2026
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the…
ModificadaMedia (5.4)0.24%—Codeless Cowidgets - Elementor4/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1.
ModificadaMedia (5.4)0.35%—Codeless Cowidgets Elementor Addons4/6/202417/6/2026
The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access…
AplazadaMedia (5.6)0.11%—Hypr PasswordlessAI21/5/202417/6/2026
Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software Update.This issue affects HYPR Passwordless: before 9.1.
AplazadaMedia (5.3)0.51%—Imran Sayed Headless CMSAI17/5/202417/6/2026
Missing Authorization vulnerability in Imran Sayed Headless CMS.This issue affects Headless CMS: from n/a through 2.0.3.
ModificadaMedia (5.4)0.26%—Visualmodo Borderless17/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless borderless allows DOM-Based XSS.This issue affects Borderless: from n/a through <= 1.7.3.
AplazadaMedia (5.5)0.18%—Intel Wireless BluetoothAI16/5/202417/6/2026
Improper access control for some Intel(R) Wireless Bluetooth products for Windows before version 23.20 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (4.7)0.36%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi software for linux before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (4.4)0.22%—Intel Wireless BluetoothAI16/5/202417/6/2026
Improper conditions check for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.20 may allow a privileged user to potentially enable denial of service via local access.
AplazadaMedia (4.3)0.22%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaAlta (8.2)0.34%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (4.3)0.43%—Intel Proset Wireless WifiAI16/5/202417/6/2026
Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
AplazadaMedia (5.5)0.49%—Paperless-ngxAI15/5/202417/6/2026
Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Starting in version 2.5.0 and prior to version 2.8.6, remote user authentication allows API access even if API access is explicitly disabled. Version 2.8.6 contains a patchc for the issue.
ModificadaMedia (5.4)0.41%—Visualmodo Borderless14/5/202417/6/2026
The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
AnalizadaAlta (8.6)0.63%—Greenwoodsoftware LessDebian LinuxNetapp Bootstrap OSNetapp HCI Storage Nodes+113/4/202417/6/2026
less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically requires use with attacker-controlled file names, such as the files extracted from an untrusted archive. Exploitation also requires the LESSOPEN environment…
ModificadaAlta (7.1)0.41%—UDX Wp-stateless6/4/202417/6/2026
The WP-Stateless – Google Cloud Storage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the dismiss_notices() function in all versions up to, and including, 3.4.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update…
AplazadaMedia (4.3)0.25%—Elecom Wireless LAN RouterAI4/4/202417/6/2026
ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.
AplazadaAlta (7.1)0.69%—Elecom Wireless LAN RouterAI4/4/202417/6/2026
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product.
AnalizadaAlta (7.4)0.29%—Cisco Wireless LAN Controller SoftwareCisco IOS XE27/3/202417/6/2026
A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed…
AnalizadaAlta (8.6)0.63%—Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software27/3/202417/6/2026
A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this…
AplazadaMedia (6.5)0.33%—Cozmoslabs Passwordless LoginAI19/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareiodata Passwordless Login passwordless-login allows Stored XSS.This issue affects Passwordless Login: from n/a through 1.1.2.
ModificadaAlta (7.5)0.94%—Intel Inet Wireless DaemonFedoraproject Fedora3/3/202417/6/2026
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
ModificadaAlta (7.5)1.1%—Intel Inet Wireless Daemon22/2/202417/6/2026
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.
ModificadaAlta (7.8)1.1%—Greenwoodsoftware Less19/2/202417/6/2026
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
AplazadaBaja (2.3)0.39%—Intel Proset WirelessAIIntel Killer WI FIAI14/2/202417/6/2026
Improper initialization for the Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
Orbitaley — Vulnerabilidades