Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
178 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.33% | 💥 PoC | Themepunch Slider Revolution | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0. | |
| Modificada | Media (5.4) | 0.28% | — | Themepunch Slider Revolution | 19/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: from n/a before 6.7.11. | |
| Aplazada | Media (4.3) | 0.60% | — | Revolut Gateway FOR WoocommerceAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7. | |
| Analizada | Alta (8.8) | 0.32% | — | Coderevolution Aiomatic | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3. | |
| Modificada | Media (6.1) | 0.29% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77. | |
| Modificada | Media (5.4) | 0.26% | — | Themepunch Slider Revolution | 4/6/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.28% | — | Themepunch Slider Revolution | 4/6/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Coderevolution Demo MY WordpressAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1. | |
| Aplazada | Alta (8.5) | 0.65% | — | Brevo Sendinblue FOR WoocommerceAI | 6/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17. | |
| Modificada | Media (5.4) | 0.42% | — | Themepunch Slider Revolution | 2/5/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (8.8) | 0.64% | — | Coderevolution WP Setup WizardAI | 25/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1. | |
| Aplazada | Crítica (9.1) | 0.48% | — | Revoworks ScvxAIRevoworks BrowserAI | 1/3/2024 | 17/6/2026 | Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using 'VirusChecker' or 'ThreatChecker' feature). If data containing malware is saved in a specific file format (eml, dmg, vhd,… | |
| Modificada | Alta (8.8) | 1.4% | — | Themepunch Slider Revolution | 8/1/2024 | 17/6/2026 | The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution. | |
| Modificada | Alta (8.8) | 0.69% | — | Themepunch Slider Revolution | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15. | |
| Modificada | Media (6.1) | 0.40% | — | Coderevolution WP Pocket Urls | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Reflected XSS.This issue affects WP Pocket URLs: from n/a through 1.0.2. | |
| Modificada | Media (5.4) | 0.39% | — | Themepunch Slider Revolution | 20/11/2023 | 17/6/2026 | Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14. | |
| Modificada | Media (5.9) | 0.35% | — | Xerox Primelink C9065 FirmwareXerox Primelink C9070 FirmwareXerox Primelink B9136 FirmwareXerox Primelink B9125 Firmware+89 | 2/11/2023 | 17/6/2026 | Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the… | |
| Modificada | Media (5.4) | 0.36% | — | F-revocrm | 6/9/2023 | 17/6/2026 | F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product. | |
| Modificada | Crítica (9.8) | 1.5% | — | F-revocrm | 6/9/2023 | 17/6/2026 | F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running. | |
| Modificada | Media (5.4) | 0.36% | — | Tridenttechnolabs Easy Slider Revolution | 17/8/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions. | |
| Modificada | Crítica (9.8) | 0.82% | — | Brevo | 26/7/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component. | |
| Modificada | Alta (8.8) | 2.5% | — | Themepunch Slider Revolution | 19/6/2023 | 17/6/2026 | The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations. | |
| Modificada | Media (6.1) | 0.49% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 5/6/2023 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against… | |
| Modificada | Media (6.8) | 0.23% | — | Deyeinverter Inverter FirmwareRevolt-power Inverter FirmwareBosswerk Inverter Firmware | 13/2/2023 | 17/6/2026 | A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to… | |
| Modificada | Alta (7.8) | 0.61% | — | Jscom Revoworks BrowserJscom Revoworks DesktopJscom Revoworks Scvx | 14/6/2022 | 17/6/2026 | Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which… |