Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.21% | — | Kod8 Software Technologies Trade Kod8 Individual AND SME WebsiteAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Software Technologies Trade Ltd. Co. Kod8 Individual and SME Website allows Reflected XSS. This issue affects Kod8 Individual and SME Website: through 03022026. NOTE: The vendor was contacted early about… | |
| Analizada | Crítica (9.3) | 1.1% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication. | |
| Analizada | Alta (8.6) | 0.31% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with… | |
| Aplazada | Media (6.3) | 0.26% | — | Schema Plugin FOR DiviAI | 3/10/2025 | 17/6/2026 | The Schema Plugin For Divi, Gutenberg & Shortcodes plugin for WordPress is vulnerable to Object Instantiation in all versions up to, and including, 4.3.2 via deserialization of untrusted input via the wpt_schema_breadcrumbs shortcode. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (8.6) | 8.2% | — | Diviotec Professional SeriesAI | 2/6/2025 | 17/6/2026 | The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and hardcoded passwords are used. | |
| Aplazada | Media (4.3) | 0.30% | — | Acmemediakits Acme-divi-modulesAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in acmemediakits ACME Divi Modules acme-divi-modules allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACME Divi Modules: from n/a through <= 1.3.5. | |
| Aplazada | Media (5.8) | 0.33% | — | Stellarwp Give - Divi Donation ModulesAI | 23/2/2025 | 17/6/2026 | Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in StellarWP Give – Divi Donation Modules give-donation-modules-for-divi allows Retrieve Embedded Sensitive Data.This issue affects Give – Divi Donation Modules: from n/a through <= 2.0.0. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Boardroom Limited Dividend Distribution TAX Election SystemAI | 18/2/2025 | 17/6/2026 | A time-based SQL injection vulnerability in the login page of BoardRoom Limited Dividend Distribution Tax Election System Version v2.0 allows attackers to execute arbitrary code via a crafted input. | |
| Aplazada | Media (6.4) | 0.40% | — | Divi Torque LiteAI | 29/1/2025 | 17/6/2026 | The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible… | |
| Analizada | Media (5.4) | 0.35% | — | Elegantthemes Carousel Maker FOR Divi | 25/1/2025 | 17/6/2026 | The Divi Carousel Maker – Image, Logo, Testimonial, Post Carousel & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Carousel and Logo Carousel in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Media (6.4) | 0.41% | — | Exclusive DiviAI | 16/11/2024 | 17/6/2026 | The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (6.3) | 0.44% | — | Bandisoft Bandiview | 3/10/2024 | 17/6/2026 | Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files. | |
| Analizada | Media (6.3) | 0.44% | — | Bandisoft Bandiview | 3/10/2024 | 17/6/2026 | Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). | |
| Analizada | Media (6.5) | 0.46% | 💥 PoC | Bandisoft Bandiview | 3/10/2024 | 17/6/2026 | Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file. | |
| Modificada | Media (5.4) | 0.26% | — | Elegantthemes Divi | 18/6/2024 | 17/6/2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will… | |
| Aplazada | Media (6.4) | 0.35% | — | Divi Torque LiteAI | 12/6/2024 | 17/6/2026 | The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘support_unfiltered_files_upload’ function in all versions up to, and including, 3.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.51% | — | Elegantthemes DiviAIElegantthemes ExtraAIElegantthemes Divi Page BuilderAI | 14/5/2024 | 17/6/2026 | The Elegant Themes Divi theme, Extra theme, and Divi Page Builder plugin for WordPress are vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘title’ parameter in versions up to, and including, 4.25.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (5.5) | 0.41% | 💥 PoC | Bandisoft Bandiview | 12/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file. | |
| Modificada | Media (5.4) | 0.33% | — | Elegantthemes Divi | 23/12/2023 | 17/6/2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'et_pb_text' shortcode in all versions up to, and including, 4.23.1 due to insufficient input sanitization and output escaping on user supplied custom field data. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 0.38% | — | Bestdivichild Business PRO | 4/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Elegantthemes Divi | 8/8/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Elegant themes Divi theme <= 4.20.2 versions. | |
| Analizada | Alta (8.8) | 2.5% | — | Elegantthemes DiviElegantthemes Divi BuilderElegantthemes Extra | 1/1/2021 | 17/6/2026 | An issue was discovered in the Divi Builder plugin, Divi theme, and Divi Extra theme before 4.5.3 for WordPress. Authenticated attackers, with contributor-level or above capabilities, can upload arbitrary files, including .php files. This occurs because the check for file extensions is on the client side. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Crítica (9.8) | 5.8% | — | Divisait Dv2eemvcDivisait Proxia PHRDivisait Proxia SuiteDivisait Sparkspace | 17/12/2019 | 17/6/2026 | Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpace 1.0 < 1.0.30, 1.1 < 1.1.2, and 1.2 < 1.2.4, and Proxia PHR 1.0 < 1.0.30 and 1.1 < 1.1.2 allows remote code execution via untrusted Java deserialization. The proxia-error cookie is insecurely… | |
| Modificada | Alta (7.5) | 1.3% | — | Diviproject Divi | 5/11/2019 | 17/6/2026 | Divi through 4.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk. |