Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.50% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Modificada | Alta (8.8) | 0.39% | — | Unlimited-elements Unlimited Elements FOR Elementor | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65. | |
| Modificada | Alta (8.8) | 0.51% | — | Unlimited-elements Unlimited Elements FOR Elementor | 6/6/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Modificada | Alta (8.8) | 0.37% | — | Unlimited-elements Unlimited Elements FOR Elementor | 5/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.109. | |
| Analizada | Alta (7.2) | 0.52% | — | Unlimited-elements Unlimited Elements FOR Elementor | 4/6/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66. | |
| Modificada | Media (4.6) | 0.26% | — | Unlimited-elements Unlimited Elements FOR Elementor | 30/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Alta (8.8) | 1.3% | — | Unlimited-elements Unlimited Elements FOR Elementor | 29/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with contributor access and above, to execute code… | |
| Modificada | Alta (8.8) | 0.45% | — | Unlimited-elements Unlimited Elements FOR Elementor | 23/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Alta (7.8) | 0.14% | — | Terabyte Unlimited Image FOR WindowsAI | 21/5/2024 | 17/6/2026 | An issue in TeraByte Unlimited Image for Windows v.3.64.0.0 and before and fixed in v.4.0.0.0 allows a local attacker to escalate privileges via the TBOFLHelper64.sys and TBOFLHelper.sys component. | |
| Modificada | Media (6.1) | 0.40% | — | Unlimited-elements Unlimited Elements FOR Elementor | 14/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.82% | — | Unlimited-elements Unlimited Elements FOR Elementor | 14/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Alta (7.2) | 1.7% | — | Unlimited-elements Unlimited Elements FOR Elementor | 14/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for… | |
| Modificada | Alta (8.8) | 0.76% | — | Unlimited-elements Unlimited Elements FOR Elementor | 24/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60. | |
| Modificada | Media (5.4) | 0.34% | — | Unlimited-elements Unlimited Elements FOR Elementor | 30/3/2024 | 17/6/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link field of an installed widget (e.g., 'Button Link') in all versions up to, and including, 1.5.96 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Modificada | Media (6.1) | 0.74% | 💥 Exploit | Unlimited-elements Unlimited Elements FOR Elementor | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a… | |
| Modificada | Alta (8.8) | 0.68% | — | Unlimited-elements Addon Library | 26/2/2024 | 17/6/2026 | The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in all versions up to, and including, 1.3.76. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several… | |
| Modificada | Alta (7.2) | 1.5% | — | Unitecms Unlimited Addons FOR Wpbakery Page Builder | 5/2/2024 | 17/6/2026 | The Unlimited Addons for WPBakery Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'importZipFile' function in versions up to, and including, 1.0.42. This makes it possible for authenticated attackers with a role that the administrator previously… | |
| Modificada | Media (6.5) | 0.65% | — | Unlimited-elements Unlimited Elements FOR Elementor | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65. | |
| Modificada | Alta (8.8) | 1.3% | — | Unlimited-elements Unlimited Elements FOR Elementor | 17/6/2023 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with… | |
| Modificada | Media (4.8) | 0.39% | — | Unlimited-elements Unlimited Elements FOR Elementor | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions. | |
| Modificada | Alta (8.8) | 0.52% | — | Xml-sitemaps Unlimited Sitemap Generator | 24/11/2021 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page. | |
| Modificada | Alta (8.8) | 1.6% | — | Unlimited Popups Project Unlimited Popups | 8/11/2021 | 17/6/2026 | The Unlimited PopUps WordPress plugin through 4.5.3 does not sanitise or escape the did GET parameter before using it in a SQL statement, available to users as low as editor, leading to an authenticated SQL Injection | |
| Modificada | Crítica (9.8) | 1.5% | — | Keepsolid VPN Unlimited | 16/3/2018 | 17/6/2026 | VPN Unlimited 4.2.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The privileged helper tool implements an XPC interface, which allows arbitrary applications to execute system commands as root. | |
| Modificada | Crítica (9.8) | 25% | — | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors. | |
| Modificada | Crítica (9.4) | 4.3% | — | Meteocontrol Web'log Basic 100Meteocontrol Web'log LightMeteocontrol Web'log PROMeteocontrol Web'log PRO Unlimited | 14/5/2016 | 17/6/2026 | Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature." |