Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

178 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.33%💥 PoCThemepunch Slider Revolution19/6/202417/6/2026
Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0.
ModificadaMedia (5.4)0.28%—Themepunch Slider Revolution19/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: from n/a before 6.7.11.
AplazadaMedia (4.3)0.60%—Revolut Gateway FOR WoocommerceAI11/6/202417/6/2026
Missing Authorization vulnerability in Revolut Revolut Gateway for WooCommerce.This issue affects Revolut Gateway for WooCommerce: from n/a through 4.9.7.
AnalizadaAlta (8.8)0.32%—Coderevolution Aiomatic9/6/202417/6/2026
Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3.
ModificadaMedia (6.1)0.29%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe4/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77.
ModificadaMedia (5.4)0.26%—Themepunch Slider Revolution4/6/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers,…
ModificadaMedia (5.4)0.28%—Themepunch Slider Revolution4/6/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for…
AplazadaCrítica (9.8)0.50%—Coderevolution Demo MY WordpressAI17/5/202417/6/2026
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.
AplazadaAlta (8.5)0.65%—Brevo Sendinblue FOR WoocommerceAI6/5/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17.
ModificadaMedia (5.4)0.42%—Themepunch Slider Revolution2/5/202417/6/2026
The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘htmltag’ parameter in all versions up to, and including, 6.7.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (8.8)0.64%—Coderevolution WP Setup WizardAI25/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.
AplazadaCrítica (9.1)0.48%—Revoworks ScvxAIRevoworks BrowserAI1/3/202417/6/2026
Protection mechanism failure issue exists in RevoWorks SCVX prior to scvimage4.10.21_1013 (when using 'VirusChecker' or 'ThreatChecker' feature) and RevoWorks Browser prior to 2.2.95 (when using 'VirusChecker' or 'ThreatChecker' feature). If data containing malware is saved in a specific file format (eml, dmg, vhd,…
ModificadaAlta (8.8)1.4%—Themepunch Slider Revolution8/1/202417/6/2026
The Slider Revolution WordPress plugin before 6.6.19 does not prevent users with at least the Author role from unserializing arbitrary content when importing sliders, potentially leading to Remote Code Execution.
ModificadaAlta (8.8)0.69%—Themepunch Slider Revolution20/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.6.15.
ModificadaMedia (6.1)0.40%—Coderevolution WP Pocket Urls15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs allows Reflected XSS.This issue affects WP Pocket URLs: from n/a through 1.0.2.
ModificadaMedia (5.4)0.39%—Themepunch Slider Revolution20/11/202317/6/2026
Contributor+ Stored Cross-Site Scripting (XSS) vulnerability in Slider Revolution <= 6.6.14.
ModificadaMedia (5.9)0.35%—Xerox Primelink C9065 FirmwareXerox Primelink C9070 FirmwareXerox Primelink B9136 FirmwareXerox Primelink B9125 Firmware+892/11/202317/6/2026
Multiple MFPs (multifunction printers) provided by FUJIFILM Business Innovation Corp. and Xerox Corporation provide a facility to export the contents of their Address Book with encrypted form, but the encryption strength is insufficient. With the knowledge of the encryption process and the encryption key, the…
ModificadaMedia (5.4)0.36%—F-revocrm6/9/202317/6/2026
F-RevoCRM 7.3 series prior to version7.3.8 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
ModificadaCrítica (9.8)1.5%—F-revocrm6/9/202317/6/2026
F-RevoCRM version7.3.7 and version7.3.8 contains an OS command injection vulnerability. If this vulnerability is exploited, an attacker who can access the product may execute an arbitrary OS command on the server where the product is running.
ModificadaMedia (5.4)0.36%—Tridenttechnolabs Easy Slider Revolution17/8/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in Trident Technolabs Easy Slider Revolution plugin <= 1.0.0 versions.
ModificadaCrítica (9.8)0.82%—Brevo26/7/202317/6/2026
SQL injection vulnerability found in PrestaShop sendinblue v.4.0.15 and before allow a remote attacker to gain privileges via the ajaxOrderTracking.php component.
ModificadaAlta (8.8)2.5%—Themepunch Slider Revolution19/6/202317/6/2026
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
ModificadaMedia (6.1)0.49%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe5/6/202317/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against…
ModificadaMedia (6.8)0.23%—Deyeinverter Inverter FirmwareRevolt-power Inverter FirmwareBosswerk Inverter Firmware13/2/202317/6/2026
A vulnerability was found in Deye/Revolt/Bosswerk Inverter MW3_15U_5406_1.47/MW3_15U_5406_1.471. It has been rated as problematic. This issue affects some unknown processing of the component Access Point Setting Handler. The manipulation with the input 12345678 leads to use of hard-coded password. It is possible to…
ModificadaAlta (7.8)0.61%—Jscom Revoworks BrowserJscom Revoworks DesktopJscom Revoworks Scvx14/6/202217/6/2026
Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which…