Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.34% | — | Ultimatemember Ultimate Member | 4/10/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.6. This is due to missing or incorrect nonce validation on the admin_init or user_action_hook… | |
| Analizada | Media (5.4) | 0.44% | — | Ultimatemember Ultimate Member | 4/10/2024 | 17/6/2026 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'um_loggedin' shortcode in all versions up to, and including, 2.8.6 due to insufficient input sanitization and output… | |
| Analizada | Media (5.4) | 0.38% | — | Dotcamp Ultimate Blocks | 30/9/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Media (6.5) | 0.50% | — | Wpwax Product Carousel Slider AND Grid UltimateAI | 23/9/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpWax Product Carousel Slider & Grid Ultimate for WooCommerce woo-product-carousel-slider-and-grid-ultimate.This issue affects Product Carousel Slider & Grid Ultimate for WooCommerce: from n/a… | |
| Analizada | Media (5.3) | 16% | 💥 Exploit | Fairsketch Rise Ultimate Project Manager | 17/9/2024 | 17/6/2026 | A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.48% | — | Ultimatemember Forumwp | 6/9/2024 | 17/6/2026 | The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated… | |
| Analizada | Crítica (9.8) | 1.1% | — | Bdthemes Ultimate Store KIT | 28/8/2024 | 17/6/2026 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_wishlist cookie in versions up to , and including, 2.0.3.… | |
| Aplazada | Media (6.4) | 0.34% | — | Logo Showcase UltimateAI | 27/8/2024 | 17/6/2026 | The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.8) | 0.85% | — | Bdthemes Ultimate Store KIT | 21/8/2024 | 17/6/2026 | The Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the _ultimate_store_kit_compare_products cookie in versions up to , and including,… | |
| Modificada | Crítica (10) | 0.54% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Modificada | Crítica (9.8) | 0.55% | — | Wpindeed Ultimate Membership PRO | 19/8/2024 | 17/6/2026 | Improper Authentication vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpindeed Ultimate Membership PROAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro.This issue affects Ultimate Membership Pro: from n/a through <= 12.7. | |
| Analizada | Media (5.4) | 0.25% | — | Bdthemes Ultimate Store KIT | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store Kit Elementor Addons: from n/a through 1.6.4. | |
| Analizada | Alta (8.8) | 0.58% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.4. | |
| Analizada | Media (5.4) | 0.26% | — | Brainstormforce Ultimate Addons FOR Beaver Builder | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite allows Stored XSS.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through 1.5.9. | |
| Modificada | Media (5.5) | 0.99% | 💥 Exploit | K7computing K7 Ultimate Security | 6/8/2024 | 17/6/2026 | K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference. | |
| Analizada | Media (5.4) | 0.33% | — | Getshortcodes Shortcodes Ultimate | 6/8/2024 | 17/6/2026 | The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Alta (7.1) | 0.96% | 💥 PoC | Webcodingplace Ultimate Classified Listings | 1/8/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (4.6) | 0.32% | — | Dotcamp Ultimate Blocks | 29/7/2024 | 17/6/2026 | The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Analizada | Media (4.7) | 0.38% | — | Webcodingplace Ultimate Classified Listings | 29/7/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Alta (7.5) | 0.76% | — | Webcodingplace Ultimate Classified Listings | 29/7/2024 | 17/6/2026 | The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the server from the listings page | |
| Aplazada | Media (5.8) | 0.40% | — | Auctionplugin Ultimate Wordpress Auction PluginAI | 27/7/2024 | 17/6/2026 | The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback' and 'resend_auction_email_callback' functions in all versions up to, and including, 4.2.7. This makes it possible for… | |
| Modificada | Media (5.4) | 0.24% | — | Dotcamp Ultimate Blocks | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks – Gutenberg Blocks Plugin allows Stored XSS.This issue affects Ultimate Blocks – Gutenberg Blocks Plugin: from n/a through 3.1.9. | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_dual_color shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Modificada | Media (5.4) | 0.29% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page Builder | 17/7/2024 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ultimate_info_banner shortcode in all versions up to, and including, 3.19.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |