Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1770 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.32% | — | Best WP Developer Gutenium BlocksAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer Gutenium Blocks gutenium allows Stored XSS.This issue affects Gutenium Blocks: from n/a through <= 1.1.7. | |
| Analizada | Media (5.7) | 0.50% | — | Wpdeveloper Essential Addons FOR Elementor | 15/11/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for… | |
| Analizada | Media (5.7) | 0.47% | — | Wpdeveloper Essential Addons FOR Elementor | 15/11/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for… | |
| Analizada | Media (5.4) | 0.30% | — | Wpdeveloper Essential Addons FOR Elementor | 15/11/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This… | |
| Analizada | Alta (7.3) | 0.24% | — | AMD Ryzen Master Monitoring Software Development KIT | 12/11/2024 | 17/6/2026 | Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Modificada | Alta (7.2) | 0.46% | — | Wpdeveloper Betterlinks | 4/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7. | |
| Modificada | Crítica (9.8) | 0.48% | — | Wpdeveloper Reviewx | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28. | |
| Analizada | Alta (8.8) | 0.42% | — | Wpdeveloper Embedpress | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpdeveloper TemplatelyAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through <= 3.1.5. | |
| Aplazada | Media (5.4) | 0.39% | — | Wpdeveloper TemplatelyAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through <= 3.1.5. | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Embedpress | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedPress: from n/a through <= 4.0.14. | |
| Modificada | Media (5.4) | 0.27% | — | Swebdeveloper Wppricing Builder | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swebdeveloper wpPricing Builder wppricing-builder-lite-responsive-pricing-table-builder allows Stored XSS.This issue affects wpPricing Builder: from n/a through <= 1.5.0. | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 16/10/2024 | 17/6/2026 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data. | |
| Analizada | Alta (8.8) | 0.46% | — | Wpdeveloper Essential Addons FOR Elementor | 16/10/2024 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the… | |
| Analizada | Media (4.3) | 0.26% | — | Wpdeveloper Essential Addons FOR Elementor | 16/10/2024 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized… | |
| Analizada | Alta (8.1) | 0.43% | — | Oracle Process Manufacturing Product Development | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Analizada | Alta (8.8) | 0.18% | — | Rockwellautomation Rslogix 5Rockwellautomation Rslogix 500Rockwellautomation Rslogix Micro DeveloperRockwellautomation Rslogix Micro Starter Lite | 14/10/2024 | 17/6/2026 | VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A feature in the affected products enables users to prepare a project file with an… | |
| Analizada | Media (6.2) | 0.16% | — | Blackberry QNX Software Development Platform | 8/10/2024 | 17/6/2026 | NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process. | |
| Analizada | Crítica (9.8) | 0.33% | — | Mediatek Software Development KITGoogle Android | 7/10/2024 | 17/6/2026 | In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09001358; Issue ID: MSV-1599. | |
| Analizada | Crítica (9.8) | 0.32% | — | Mediatek Software Development KITGoogle Android | 7/10/2024 | 17/6/2026 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998901; Issue ID: MSV-1602. | |
| Analizada | Crítica (9.8) | 0.33% | — | Mediatek IOT YoctoMediatek Software Development KITGoogle Android | 7/10/2024 | 17/6/2026 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998449; Issue ID: MSV-1603. | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Essential Blocks | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.8.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpdeveloperr Confetti Fall AnimationAI | 30/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel Confetti Fall Animation confetti-fall-animation allows Stored XSS.This issue affects Confetti Fall Animation: from n/a through <= 1.3.0. | |
| Modificada | Media (5.4) | 0.34% | — | Wpdeveloperr Confetti Fall Animation | 25/9/2024 | 17/6/2026 | The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.37% | — | Wpdeveloper Essential Addons FOR Elementor | 13/9/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping… |