Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
576 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | 💥 Exploit | Wpzoom Social Icons Widget | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WPZOOM Social Icons Widget & Block by WPZOOM.This issue affects Social Icons Widget & Block by WPZOOM: from n/a through 4.2.15. | |
| Aplazada | Media (6.5) | 0.42% | — | Marketing Fire LLC Widget Options ExtendedAI | 8/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Marketing Fire, LLC Widget Options - Extended.This issue affects Widget Options - Extended: from n/a through 5.1.0. | |
| Modificada | Media (5.4) | 0.28% | — | Eltiempoen Weather Widget PRO | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in El tiempo Weather Widget Pro allows Stored XSS.This issue affects Weather Widget Pro: from n/a through 1.1.40. | |
| Modificada | Media (5.4) | 0.31% | — | Johnnash1975 Easy Social Like BOX Popup Sidebar Widget | 6/6/2024 | 17/6/2026 | The Easy Social Like Box – Popup – Sidebar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cardoza_facebook_like_box' shortcode in all versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Alta (8.8) | 0.93% | — | Codeless Cowidgets Elementor Addons | 6/6/2024 | 17/6/2026 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the… | |
| Modificada | Media (5.4) | 0.28% | — | Axelerant Testimonials Widget | 6/6/2024 | 17/6/2026 | The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.24% | — | Codeless Cowidgets - Elementor | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Codeless Cowidgets – Elementor Addons allows Stored XSS.This issue affects Cowidgets – Elementor Addons: from n/a through 1.1.1. | |
| Modificada | Media (5.4) | 0.35% | — | Codeless Cowidgets Elementor Addons | 4/6/2024 | 17/6/2026 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access… | |
| Aplazada | Media (5.3) | 0.34% | — | Awplife Contact Form WidgetAI | 3/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in A WP Life Contact Form Widget.This issue affects Contact Form Widget: from n/a through 1.3.9. | |
| Aplazada | Alta (8) | 0.60% | — | 140 Widgets Best Addons FOR Elementor FreeAI | 23/5/2024 | 17/6/2026 | The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.3.1 via deserialization of untrusted input in the 'export_content' function. This allows authenticated attackers, with contributor-level permissions and above, to inject a PHP… | |
| Aplazada | Media (6.4) | 0.29% | — | Jquery T Countdown WidgetAI | 23/5/2024 | 17/6/2026 | The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tminus shortcode in all versions up to, and including, 2.3.25 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.36% | — | Siteorigin Widgets Bundle | 22/5/2024 | 17/6/2026 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 1.60.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.39% | — | Wpzoom Social Icons Widget | 21/5/2024 | 17/6/2026 | The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.42% | — | Envothemes Envo's Elementor Templates & Widgets FOR Woocommerce | 14/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's Elementor Templates & Widgets for WooCommerce allows Stored XSS.This issue affects Envo's Elementor Templates & Widgets for WooCommerce: from n/a through 1.4.8. | |
| Aplazada | Media (5.9) | 0.44% | — | Archives Calendar WidgetAI | 14/5/2024 | 17/6/2026 | Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions. | |
| Aplazada | Media (6.5) | 0.36% | — | Codename065 Sliding WidgetsAI | 14/5/2024 | 17/6/2026 | Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0. | |
| Aplazada | Media (6.5) | 0.26% | — | Themesgrove WidgetkitAI | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.4.8. | |
| Aplazada | Media (5.3) | 0.40% | — | Themesgrove WidgetkitAI | 6/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0. | |
| Aplazada | Media (5.5) | 0.15% | — | Motorola Time Weather WidgetAI | 3/5/2024 | 17/6/2026 | An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local application to acquire the location of the device without authorization. | |
| Aplazada | Media (5.9) | 0.32% | — | Lorna Timbah Accessibility WidgetAI | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lorna Timbah (webgrrrl) Accessibility Widget allows Stored XSS.This issue affects Accessibility Widget: from n/a through 2.2. | |
| Modificada | Media (6.1) | 0.33% | — | Codebard's Patron Button AND Widgets FOR Patreon | 3/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeBard CodeBard's Patron Button and Widgets for Patreon allows Reflected XSS.This issue affects CodeBard's Patron Button and Widgets for Patreon: from n/a through 2.2.0. | |
| Aplazada | Media (5.5) | 0.29% | — | Pixel Industry Tweetscroll WidgetAI | 2/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixel Industry TweetScroll Widget allows Stored XSS.This issue affects TweetScroll Widget: from n/a through 1.3.7. | |
| Aplazada | Media (6.4) | 0.42% | — | Wpzoom Icon WidgetAI | 2/5/2024 | 17/6/2026 | The Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Aplazada | Media (5.4) | 0.30% | — | Mahesh Vora WP Page Post Widget CloneAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Mahesh Vora WP Page Post Widget Clone.This issue affects WP Page Post Widget Clone: from n/a through 1.0.1. | |
| Aplazada | Media (6.5) | 0.33% | — | Wpopal Opal Widgets FOR ElementorAI | 29/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9. |