Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1770 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.39%—Wpdeveloper Essential Addons FOR Elementor11/9/202417/6/2026
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user…
AnalizadaMedia (4.8)0.35%—Just-a-web-developer Floating Contact Button10/9/202417/6/2026
The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
AnalizadaAlta (7.5)0.69%—Dfinity Canister Developer KIT FOR THE Internet Computer5/9/202417/6/2026
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFutureState. A bug in the polling implementation of the CallFuture allows multiple…
AnalizadaMedia (5.4)0.29%—Wpdeveloper Embedpress29/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper EmbedPress allows Stored XSS.This issue affects EmbedPress: from n/a through 4.0.8.
AnalizadaMedia (6.4)0.31%—Amazon AWS Cloud Development KIT27/8/202417/6/2026
The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own applications which are converted to AWS CloudFormation templates during deployment to a customer’s AWS account. CDK contains pre-built components called "constructs" that…
AnalizadaCrítica (9.8)0.50%—Wpdeveloper Embedpress19/8/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper EmbedPress allows PHP Local File Inclusion.This issue affects EmbedPress: from n/a through 4.0.9.
ModificadaMedia (6.7)0.24%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Incorrect privilege assignment in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.7)0.21%—Zoom Meeting Software Development KITZoom RoomsZoom Workplace Desktop14/8/202417/6/2026
Improper privilege management in the installer for Zoom Workplace Desktop App for macOS, Zoom Meeting SDK for macOS and Zoom Rooms Client for macOS before 6.1.5 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.18%—Zoom Meeting Software Development KITZoom Workplace Desktop14/8/202417/6/2026
Untrusted search path in the installer for Zoom Workplace Desktop App for macOS and Zoom Meeting SDK for macOS before 6.1.0 may allow a privileged user to conduct an escalation of privilege via local access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.57%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Buffer overflow in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct a denial of service via network access.
AnalizadaMedia (4.9)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Sensitive information disclosure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.49%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
ModificadaMedia (4.9)0.49%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/8/202417/6/2026
Missing authorization in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow a privileged user to conduct an information disclosure via network access.
AnalizadaMedia (6.5)0.51%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+114/8/202417/6/2026
Sensitive information exposure in some Zoom Workplace Apps, SDKs, Rooms Clients, and Rooms Controllers may allow an authenticated user to conduct an information disclosure via network access.
AnalizadaMedia (5.4)0.15%—Intel Field Programmable Gate Array Software Development KIT FOR Opencl14/8/202417/6/2026
Uncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (8.8)0.57%—Wpdeveloper Betterdocs13/8/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a through 3.5.8.
AnalizadaMedia (5.4)0.44%—Wpdeveloper Essential Addons FOR Elementor13/8/202417/6/2026
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘no_more_items_text’ parameter in all versions up to, and including, 5.9.27 due to insufficient input sanitization and output escaping. This…
AnalizadaMedia (5.4)0.26%—Wpdeveloper Betterdocs12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloper BetterDocs allows Stored XSS.This issue affects BetterDocs: from n/a through 3.5.8.
AnalizadaMedia (5.4)0.44%—Wpdeveloper Essential Blocks2/8/202417/6/2026
The Essential Blocks WordPress plugin before 4.7.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (5.4)0.29%—Wpdeveloper Essential Addons FOR Elementor1/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite.This issue affects Essential Addons for Elementor: from n/a through <= 5.9.26.
AplazadaCrítica (9.8)0.51%—Hangzhou Xiongwei Technology Development Restaurant Digital Comprehensive Management PlatformAI26/7/202417/6/2026
An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password resets.
AnalizadaAlta (8.1)0.39%—Oracle Process Manufacturing Product Development16/7/202417/6/2026
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process…