Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.62%—Coderevolution Echo RSS Feed Post Generator1/10/202417/6/2026
The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for…
AnalizadaMedia (5.4)0.32%—Themepunch Slider Revolution1/10/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…
AnalizadaMedia (5.3)0.35%—Coderevolution Aiomatic27/7/202417/6/2026
The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it…
ModificadaMedia (4.8)0.26%—Themepunch Slider Revolution21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13.
ModificadaAlta (8.8)0.33%💥 PoCThemepunch Slider Revolution19/6/202417/6/2026
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.
ModificadaMedia (5.4)0.28%—Themepunch Slider Revolution19/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: from n/a before 6.7.11.
AnalizadaAlta (8.8)0.32%—Coderevolution Aiomatic9/6/202417/6/2026
Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3.
ModificadaMedia (5.4)0.26%—Themepunch Slider Revolution4/6/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers,…
ModificadaMedia (5.4)0.28%—Themepunch Slider Revolution4/6/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for…
AplazadaCrítica (9.8)0.50%—Coderevolution Demo MY WordpressAI17/5/202417/6/2026
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.
ModificadaMedia (5.4)0.42%—Themepunch Slider Revolution2/5/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (8.8)0.64%—Coderevolution WP Setup WizardAI25/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.
ModificadaAlta (8.8)1.4%—Themepunch Slider Revolution8/1/202417/6/2026
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
ModificadaAlta (8.8)0.69%—Themepunch Slider Revolution20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
ModificadaMedia (6.1)0.40%—Coderevolution WP Pocket Urls15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Reflected XSS.This issue affects WP Pocket URLs: from n/a through 1.0.2.
ModificadaMedia (5.4)0.39%—Themepunch Slider Revolution20/11/202317/6/2026
Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.
ModificadaMedia (5.4)0.36%—Tridenttechnolabs Easy Slider Revolution17/8/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions.
ModificadaAlta (8.8)2.5%—Themepunch Slider Revolution19/6/202317/6/2026
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
ModificadaAlta (7.2)9.3%💥 ExploitModx Revolution26/2/202217/6/2026
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
ModificadaCrítica (9.1)2.4%—Modx Revolution31/10/202117/6/2026
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
ModificadaCrítica (9.8)1.5%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.8)1.1%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.6)1.2%—Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+116/9/202017/6/2026
A DNS rebinding vulnerability in the Freebox OS web interface in Freebox Server before 4.2.3.
ModificadaCrítica (9.6)1.00%—Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+116/9/202017/6/2026
A DNS rebinding vulnerability in the UPnP IGD implementations in Freebox v5 before 1.5.29 and Freebox Server before 4.2.3.
ModificadaAlta (8.8)0.53%—Freebox Revolution FirmwareFreebox Mini FirmwareFreebox ONE FirmwareFreebox Delta Firmware+116/9/202017/6/2026
A CSRF vulnerability in the UPnP MediaServer implementation in Freebox Server before 4.2.3.