Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.75%—Elementor Website Builder5/4/202117/6/2026
In the Elementor Website Builder WordPress plugin before 3.1.4, the column element (includes/elements/column.php) accepts an ‘html_tag’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’…
ModificadaMedia (6.1)0.83%—Elementor Website Builder6/1/202117/6/2026
The Elementor Website Builder plugin before 3.0.14 for WordPress does not properly restrict SVG uploads.
ModificadaMedia (5.4)0.69%—Elementor Website Builder31/8/202017/6/2026
An issue was discovered in the Elementor plugin through 2.9.13 for WordPress. An authenticated attacker can achieve stored XSS via the Name Your Template field.
ModificadaMedia (6.5)0.99%—Elementor Website Builder21/8/202017/6/2026
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
ModificadaMedia (5.4)1.3%—Elementor Website Builder28/1/202017/6/2026
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
ModificadaCrítica (9.8)1.7%—Elementor Website Builder22/1/202017/6/2026
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
ModificadaAlta (7.5)2.3%💥 ExploitEtoshop Dynamic BIZ Website Builder Quickweb21/12/201317/6/2026
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.
ModificadaAlta (7.5)8.4%💥 ExploitGrafx Software Company Website Builder2/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter to (1) cls_headline_prod.php, (2) cls_listorders.php, or (3) cls_viewpastorders.php in include/, different vectors than…
ModificadaMedia (6.8)3.5%💥 ExploitGrafx Company Website Builder PRO20/3/200716/6/2026
PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.
ModificadaAlta (7.5)1.1%—Etoshop Dynamic BIZ Website Builder Quickweb5/7/200516/6/2026
SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.