Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
70 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Stylemixthemes Consulting Elementor WidgetsAI | 31/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows DOM-Based XSS.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.5) | 0.39% | — | Stylemixthemes Consulting Elementor WidgetsAI | 31/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2. | |
| Aplazada | Alta (7.5) | 0.42% | — | Stylemixthemes ConsultingAI | 31/10/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through < 6.7.5. | |
| Aplazada | Crítica (9.8) | 0.35% | — | Fayton Software AND Consulting Services Fayton.pro ERPAI | 29/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.Pro ERP allows SQL Injection. This issue affects fayton.Pro ERP: through 20250929. | |
| Aplazada | Alta (8.7) | 0.26% | — | Nedatec Consulting PrevengosAI | 25/9/2025 | 17/6/2026 | SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in… | |
| Aplazada | Alta (8.6) | 0.45% | — | Yordam Information Technology Consulting Education AND Electrical Systems Industry Trade Yordam KatalogAI | 25/9/2025 | 17/6/2026 | Path Traversal: 'dir/../../filename' vulnerability in Yordam Information Technology Consulting Education and Electrical Systems Industry Trade Inc. Yordam Katalog allows Path Traversal. This issue affects Yordam Katalog: before 21.7. | |
| Aplazada | Crítica (10) | 1.0% | — | Talentsys Consulting Inka.netAI | 23/9/2025 | 25/9/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry Inc. Inka.Net allows Command Injection. This issue affects Inka.Net: before 6.7.1. | |
| Aplazada | Baja (2.1) | 0.34% | — | Yida Ecms Consulting Enterprise Management SystemAI | 14/9/2025 | 17/6/2026 | A vulnerability was found in Yida ECMS Consulting Enterprise Management System 1.0. This affects an unknown part of the file /login.do of the component POST Request Handler. The manipulation of the argument requestUrl results in cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Alta (7) | 0.40% | — | Evolution Consulting KFT HrmasterAI | 21/8/2025 | 5/7/2026 | HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstname) field, which will be sent out in an email resulting in possible Phishing scenarios against any, previously not registered, email address. | |
| Aplazada | Alta (7.1) | 0.26% | — | Designthemes Ofiz Wordpress Business Consulting ThemeAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Ofiz - WordPress Business Consulting Theme ofiz allows Reflected XSS.This issue affects Ofiz - WordPress Business Consulting Theme: from n/a through <= 2.0. | |
| Aplazada | Alta (8.1) | 0.78% | — | Gavias Vizeon - Business ConsultingAI | 23/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Vizeon - Business Consulting vizeon allows PHP Local File Inclusion.This issue affects Vizeon - Business Consulting: from n/a through < 1.2.1. | |
| Aplazada | Media (6.5) | 0.37% | — | Willowsconsulting Gdpr Personal Data ReportsAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in willowsconsulting GDPR Personal Data Reports gdpr-personal-data-reports allows Stored XSS.This issue affects GDPR Personal Data Reports: from n/a through <= 1.0.5. | |
| Modificada | Alta (8.8) | 0.53% | — | Stylemixthemes Consulting Elementor WidgetsStylemixthemes Masterstudy Elementor Widgets | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Masterstudy Elementor Widgets, StylemixThemes Consulting Elementor Widgets.This issue affects Masterstudy Elementor Widgets: from n/a through 1.2.2; Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Modificada | Alta (8.8) | 0.53% | — | Stylemixthemes Consulting Elementor Widgets | 24/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Modificada | Alta (8.8) | 1.2% | — | Stylemixthemes Consulting Elementor Widgets | 24/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor… | |
| Modificada | Crítica (9.8) | 0.61% | — | Stylemixthemes Consulting Elementor Widgets | 24/6/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0. | |
| Aplazada | Alta (7.3) | 0.50% | — | Stylemixthemes ConsultingAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting allows PHP Local File Inclusion.This issue affects Consulting: from n/a through 6.5.6. | |
| Analizada | Alta (8.8) | 0.28% | — | Mandsconsulting Email Before Download | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7. | |
| Modificada | Alta (7.5) | 0.56% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandle StartTransaction messages containing additional, arbitrary properties, or duplicate properties. The last occurrence of a duplicate property is accepted. This could be… | |
| Modificada | Alta (7.5) | 0.53% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors. NOTE: the… | |
| Modificada | Alta (7.5) | 0.71% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. A StopTransaction message with any random transactionId terminates active transactions. | |
| Modificada | Alta (7.5) | 0.71% | — | Dallmann-consulting Open Charge Point Protocol | 7/12/2023 | 17/6/2026 | An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It does not validate the length of the chargePointVendor field in a BootNotification message, potentially leading to server instability and a denial of service when processing excessively large… | |
| Modificada | Crítica (9.8) | 0.67% | — | Turaconsulting Signalix | 15/9/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tura Signalix allows SQL Injection. This issue affects Signalix: 7T_0228. | |
| Modificada | Crítica (9.8) | 0.60% | — | Atm-consulting Dolibarr Module Quicksupplierprice | 20/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in ATM Consulting dolibarr_module_quicksupplierprice up to 1.1.6. Affected by this issue is the function upatePrice of the file script/interface.php. The manipulation leads to sql injection. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Alta (8.8) | 1.4% | — | Mandsconsulting Email Before Download | 29/11/2021 | 17/6/2026 | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues |