Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

496 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the accordion widget (includes/widgets/accordion.php) accepts a ‘title_html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified…
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the divider widget (includes/widgets/divider.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’…
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the heading widget (includes/widgets/heading.php) accepts a ‘header_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’…
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’…
ModificadaMedia (6.1)0.83%—Elementor Website Builder6/1/202117/6/2026
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
ModificadaCrítica (9.8)1.7%—Websitebaker1/10/202017/6/2026
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
ModificadaMedia (5.4)0.69%—Elementor Website Builder31/8/202017/6/2026
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
ModificadaMedia (6.5)0.99%—Elementor Website Builder21/8/202017/6/2026
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
ModificadaMedia (5.4)1.3%—Elementor Website Builder28/1/202017/6/2026
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
ModificadaCrítica (9.8)1.7%—Elementor Website Builder22/1/202017/6/2026
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
ModificadaAlta (7.5)1.2%—Websitebaker21/1/202016/6/2026
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
ModificadaAlta (8.8)0.50%—Websitebaker14/1/202016/6/2026
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate confirmation for sensitive transactions.
ModificadaAlta (7.2)1.1%—Websitebaker14/1/202016/6/2026
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploaded files with .htaccess, .php4, .php5, and .phtl extensions.
ModificadaCrítica (9.8)2.3%—Education Website Project Education Website19/6/201917/6/2026
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
ModificadaMedia (5.4)0.64%—Chartered Accountant \ Auditor Website Project6/6/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
ModificadaMedia (5.9)1.8%—Yarnpkg Website16/5/201917/6/2026
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with…
ModificadaMedia (6.5)1.4%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has directory traversal via a direct request for a listing of an image directory such as an assets/ directory.
ModificadaMedia (6.5)1.6%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 allows remote attackers to cause a denial of service (unrecoverable blank profile) via crafted JavaScript code in the First Name and Last Name field.
ModificadaMedia (5.4)0.65%—Chartered Accountant \ Auditor Website Project21/3/201917/6/2026
PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has HTML injection via the First Name field.
ModificadaMedia (5.3)1.6%—Website Seller Script Project Website Seller Script21/3/201917/6/2026
PHP Scripts Mall Website Seller Script 2.0.5 allows full Path Disclosure via a request for an arbitrary image URL such as a .png file.
ModificadaMedia (6.5)0.94%—Auction Website Script Project Auction Website Script23/2/201917/6/2026
PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount.
ModificadaAlta (8.8)0.50%—Universal Website Asthis30/12/201817/6/2026
UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.
ModificadaMedia (5.4)0.53%—Website Seller Script Project Website Seller Script28/12/201817/6/2026
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a Profile field such as Company Address, a related issue to CVE-2018-15896.
ModificadaMedia (6.1)0.68%—Phpscriptsmall Website Seller Script4/10/201817/6/2026
PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature.
ModificadaMedia (6.5)1.1%—Website Seller Script Project Website Seller Script28/8/201817/6/2026
PHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, Company Name, or Fax field, as demonstrated by crossPwn.
Orbitaley — Vulnerabilidades