Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2732▼ 549 respecto a la semana anterior
Críticas / altas1295▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.42% | — | Wponlinesupport Featured Post CreativeAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Featured Post Creative allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Featured Post Creative: from n/a through 1.2.7. | |
| Analizada | Media (5.4) | 0.26% | — | Creativethemes Blocksy | 5/12/2024 | 17/6/2026 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter in all versions up to, and including, 2.0.77 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (6.5) | 0.32% | — | Creative Brahma Multifox PlusAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Brahma Multifox Plus multifox-plus allows DOM-Based XSS.This issue affects Multifox Plus: from n/a through <= 1.1.6. | |
| Aplazada | Media (6.5) | 0.37% | — | Keonthemes Creative BlocksAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keonthemes Creative Blocks creative-blocks allows Stored XSS.This issue affects Creative Blocks: from n/a through <= 1.0.1. | |
| Aplazada | Media (6.5) | 0.39% | — | Magnetic Creative Inline Click TO TweetAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnetic Creative Inline Click To Tweet inline-click-to-tweet allows DOM-Based XSS.This issue affects Inline Click To Tweet: from n/a through <= 1.0.0. | |
| Aplazada | Crítica (10) | 1.4% | 💥 PoC | Arttia Creative Datasets ManagerAI | 14/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Arttia Creative Datasets Manager by Arttia Creative datasets-manager-by-arttia-creative.This issue affects Datasets Manager by Arttia Creative: from n/a through <= 1.5. | |
| Modificada | Media (5.4) | 0.21% | — | Jumpstartcreatives Media Modal | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmabugay Media Modal media-modal allows DOM-Based XSS.This issue affects Media Modal: from n/a through <= 1.0.2. | |
| Aplazada | Media (5.4) | 0.32% | — | Creative Motion Clearfy CacheAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4. | |
| Aplazada | Media (4.3) | 0.39% | — | Creativemotion Social Slider FeedAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2. | |
| Aplazada | Media (6.5) | 0.50% | — | Creative Motion Robin Image OptimizerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9. | |
| Aplazada | Media (6.5) | 0.49% | — | Creativemotion Titan Anti-spam SecurityAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6. | |
| Aplazada | Media (5.3) | 0.28% | — | Creative Labs XficonnectAI | 14/10/2024 | 17/6/2026 | An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process. | |
| Aplazada | Alta (8.8) | 0.44% | — | Creativeon WhmpressAI | 19/8/2024 | 17/6/2026 | Missing Authorization vulnerability in creativeon WHMpress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WHMpress: from n/a through 6.2-revision-5. | |
| Aplazada | Alta (7.1) | 0.27% | — | Creativeon WhmpressAI | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeon WHMpress allows Reflected XSS.This issue affects WHMpress: from n/a through 6.2-revision-5. | |
| Modificada | Media (5.4) | 0.26% | — | Creativeinteractivemedia Transition Slider | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in creativeinteractivemedia Transition Slider – Responsive Image Slider and Gallery allows Stored XSS.This issue affects Transition Slider – Responsive Image Slider and Gallery: from n/a through 2.20.3. | |
| Analizada | Media (6.1) | 0.67% | — | Creativeitem Academy LMS | 9/7/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the string parameter. | |
| Modificada | Alta (7.1) | 0.30% | — | Adobe Creative Cloud Desktop Application | 13/6/2024 | 17/6/2026 | Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to load and execute malicious libraries, leading to arbitrary file delete. Exploitation of this issue… | |
| Aplazada | Media (5.4) | 0.39% | — | Hahncreativegroup WP TranslateAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in HahnCreativeGroup WP Translate.This issue affects WP Translate: from n/a through 5.3.0. | |
| Aplazada | Media (4.3) | 0.28% | — | Wpcreativeidea Advanced Testimonial Carousel FOR ElementorAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in wpcreativeidea Advanced Testimonial Carousel for Elementor.This issue affects Advanced Testimonial Carousel for Elementor: from n/a through 3.0.0. | |
| Modificada | Media (5.4) | 0.29% | — | Creativethemes Blocksy | 5/6/2024 | 17/6/2026 | The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all versions up to, and including, 2.0.50 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (4.9) | 0.26% | — | Creativethemes Blocksy Companion | 3/6/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Creative Themes Blocksy Companion blocksy-companion.This issue affects Blocksy Companion: from n/a through <= 2.0.42. | |
| Modificada | Media (5.4) | 0.26% | — | Creativethemes Blocksy | 21/5/2024 | 17/6/2026 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in all versions up to, and including, 2.0.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Aplazada | Media (4.3) | 0.19% | — | Creative Motion Clearfy CacheAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1. | |
| Aplazada | Alta (8.2) | 0.50% | — | Room 34 Creative Services ICS CalendarAI | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF) vulnerability in Room 34 Creative Services, LLC ICS Calendar ics-calendar allows Absolute Path Traversal, : Server Side Request Forgery.This issue affects ICS Calendar: from n/a through 10.12.0.3. | |
| Modificada | Media (5.4) | 0.43% | — | Creativethemes Blocksy Companion | 14/5/2024 | 17/6/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG uploads in versions up to, and including, 2.0.45 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above, to inject… |