Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (1.3) | 0.39% | — | Orange View Limited Dualsafe Password Manager AND Digital Vault ExtensionAI | 17/8/2026 | 20/8/2026 | A flaw has been found in Orange View Limited DualSafe Password Manager & Digital Vault Extension up to 1.4.35 on Chrome. Affected is an unknown function of the component postMessage-based Bridge. Executing a manipulation can lead to information disclosure. The attack can be launched remotely. A high complexity level… | |
| Aplazada | Media (6.5) | 0.44% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 6/8/2026 | 12/8/2026 | Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/8/2026 | 12/8/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.15. | |
| Analizada | Media (6.5) | 0.34% | — | Widgetfactorylimited JCE | 29/7/2026 | 5/8/2026 | Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management permissions to rename files to otherwise… | |
| Aplazada | Alta (8.8) | 0.51% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 20/7/2026 | 21/7/2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a malicious review on the targeted business's Google listing to deliver… | |
| Aplazada | Alta (7.1) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Crítica (9.9) | 0.48% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/6/2026 | 17/6/2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. | |
| Analizada | Crítica (10) | 16% | ⚠ Explotación activa | Widgetfactorylimited JCE | 5/6/2026 | 23/7/2026 | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution. | |
| Aplazada | Media (5.3) | 0.21% | — | Live Chat UnlimitedAI | 4/6/2026 | 22/7/2026 | Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area, enabling cookie theft or forced… | |
| Aplazada | Crítica (9.8) | 0.51% | — | Jinan USR IOT Technology Limited Usr-w610AI | 29/5/2026 | 21/7/2026 | Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials can be extracted through firmware analysis and used to authenticate to device services. | |
| Aplazada | Alta (8.5) | 0.36% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection. This issue affects Unlimited Elements For Elementor: from n/a through 2.0.8. | |
| Aplazada | Media (6.5) | 0.55% | — | Unlimited-elements Unlimited ElementsAI | 14/5/2026 | 17/6/2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.7. This is due to insufficient input sanitization and the use of deprecated escaping functions combined with direct… | |
| Aplazada | Media (6.5) | 0.35% | — | ALL IN ONE WP Migration All-in-one WP Migration Unlimited ExtensionAI | 6/5/2026 | 24/7/2026 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data.… | |
| Aplazada | Alta (7.2) | 1.7% | — | Profelis Information AND Consulting Trade AND Industry Limited Company SambaboxAI | 4/5/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3. | |
| Aplazada | Media (5.1) | 0.27% | — | Kanata Limited CMS AlayaAI | 23/4/2026 | 17/6/2026 | CMS ALAYA provided by KANATA Limited contains an SQL injection vulnerability. Information stored in the database may be obtained or altered by an attacker with access to the administrative interface. | |
| Aplazada | Alta (7.5) | 0.74% | — | Unlimited-elements Unlimited ElementsAI | 17/4/2026 | 17/6/2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Arbitrary File Read via the Repeater JSON/CSV URL parameter in versions up to, and including, 2.0.6. This is due to insufficient path traversal sanitization in the URLtoRelative() and urlToPath() functions, combined with the ability to enable… | |
| Analizada | Media (6.9) | 0.18% | — | Compuphase Termite | 4/4/2026 | 24/7/2026 | Termite 3.4 contains a buffer overflow vulnerability in the User interface language settings field that allows local attackers to cause a denial of service by supplying an excessively long string. Attackers can paste a 2000-byte payload into the Settings User interface language field to crash the application. | |
| Aplazada | Alta (7.1) | 0.25% | — | Themehunk Gutenberg Blocks Unlimited-blocksAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeHunk Gutenberg Blocks unlimited-blocks allows Reflected XSS.This issue affects Gutenberg Blocks: from n/a through <= 1.2.8. | |
| Aplazada | Alta (7.2) | 0.42% | — | Unlimited-elements Unlimited ElementsAI | 10/3/2026 | 17/6/2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in the admin Form Entries Trash view. This… | |
| Analizada | Media (5.3) | 0.40% | — | Zeroae Zae-limiter | 25/2/2026 | 17/6/2026 | zae-limiter is a rate limiting library using the token bucket algorithm. Prior to version 0.10.1, all rate limit buckets for a single entity share the same DynamoDB partition key (`namespace/ENTITY#{id}`). A high-traffic entity can exceed DynamoDB's per-partition throughput limits (~1,000 WCU/sec), causing throttling… | |
| Aplazada | Alta (8.5) | 0.13% | — | Keepsolid VPN UnlimitedAI | 3/2/2026 | 17/6/2026 | VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious executables into the service binary path. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\VPN Unlimited\' to replace the service executable and gain elevated system privileges. | |
| Aplazada | Media (5.4) | 0.20% | — | Unlimited-elements Unlimited ElementsAI | 3/2/2026 | 17/6/2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Border Hero widget's Button Link field in versions up to 2.0.1. This is due to insufficient input sanitization and output escaping on user-supplied URLs. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (8.2) | 0.34% | — | Mitel CXMitel Micontact Center Business | 15/1/2026 | 17/6/2026 | A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10.2.0.10 and Mitel CX through 1.1.0.1 could allow an unauthenticated attacker to conduct a Cross-Site Scripting (XSS) attack due to insufficient input validation. A successful exploit requires user interaction where the email… | |
| Analizada | Crítica (9.4) | 0.41% | — | Mitel Mivoice Mx-one | 15/1/2026 | 17/6/2026 | A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0.14) could allow an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication mechanisms. A successful exploit could allow an attacker to gain unauthorized… | |
| Aplazada | Alta (7.1) | 0.22% | — | Vernon Systems Limited Ehive SearchAI | 8/1/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vernon Systems Limited eHive Search ehive-search allows Reflected XSS.This issue affects eHive Search: from n/a through <= 2.5.0. |