Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.54% | — | Unfoldwp Magazine EliteAI | 28/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in unfoldwp Magazine Elite magazine-elite allows PHP Local File Inclusion.This issue affects Magazine Elite: from n/a through <= 1.2.4. | |
| Analizada | Alta (8.8) | 0.54% | — | Elite Project Elite | 22/8/2025 | 17/6/2026 | OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability. | |
| Aplazada | Alta (7.1) | 0.24% | — | Creativemedia Elite Video PlayerAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Reflected XSS.This issue affects Elite Video Player: from n/a through <= 10.0.5. | |
| Analizada | Media (5.4) | 0.25% | — | Pixelite Events Manager | 9/7/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Media (6.1) | 0.28% | — | Pixelite Events Manager | 9/7/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Analizada | Alta (7.5) | 67% | 💥 Exploit | Pixelite Events Manager | 9/7/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Aplazada | Alta (8.1) | 0.58% | — | Real-web RealtyeliteAI | 27/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in real-web RealtyElite realtyelite allows PHP Local File Inclusion.This issue affects RealtyElite: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.5) | 0.48% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial PIN Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.39% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial DLB_SlaveRegister Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to… | |
| Analizada | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial autocharge Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required… | |
| Analizada | Media (6.8) | 0.34% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial wLength Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.39% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is not required… | |
| Analizada | Media (6.3) | 0.27% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial ble_process_esp32_msg Misinterpretation of Input Vulnerability. This vulnerability allows network-adjacent attackers to inject arbitrary AT commands on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. Authentication is not required to exploit… | |
| Analizada | Alta (7.5) | 0.28% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Firmware Downgrade Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain the ability to pair a… | |
| Analizada | Alta (7.5) | 0.17% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Origin Validation Error Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Wallbox Commercial. An attacker must first obtain the ability to pair a malicious… | |
| Analizada | Media (6.5) | 0.55% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Serial Number Exposed Dangerous Method Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Autel MaxiCharger AC Wallbox Commercial EV chargers. Authentication is required to exploit this… | |
| Analizada | Alta (8.8) | 0.41% | — | Autel Maxicharger AC Elite Business C50 FirmwareAutel Maxicharger AC PRO FirmwareAutel Maxicharger AC Ultra FirmwareAutel Maxicharger DC Compact Mobile Firmware+5 | 25/6/2025 | 17/6/2026 | Autel MaxiCharger AC Wallbox Commercial Technician API Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of Autel MaxiCharger AC Wallbox Commercial charging stations. An attacker must first obtain a low-privileged… | |
| Aplazada | Alta (7.1) | 0.26% | — | Creativemedia Elite Video PlayerAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Stored XSS.This issue affects Elite Video Player: from n/a through <= 10.0.5. | |
| Aplazada | Media (5.4) | 0.15% | — | Creativemedia Elite Video PlayerAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in _CreativeMedia_ Elite Video Player elite-video-player allows Cross Site Request Forgery.This issue affects Elite Video Player: from n/a through <= 10.0.5. | |
| Modificada | Alta (8.8) | 0.17% | — | Wpwebelite Woocommerce Social Login | 16/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpweb WooCommerce Social Login woo-social-login allows Cross Site Request Forgery.This issue affects WooCommerce Social Login: from n/a through < 2.8.3. | |
| Aplazada | Media (6.5) | 0.36% | — | Wpelite HMH Footer Builder FOR ElementorAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPelite HMH Footer Builder For Elementor hmh-footer-builder-for-elementor allows Stored XSS.This issue affects HMH Footer Builder For Elementor: from n/a through <= 1.0. | |
| Analizada | Alta (7.5) | 0.60% | — | Pixelite Events Manager | 21/2/2025 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the active_status parameter in all versions up to, and including, 6.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Aplazada | Media (6.5) | 0.29% | — | Pixelite WP FullcalendarAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Stored XSS.This issue affects WP FullCalendar: from n/a through <= 1.5. | |
| Modificada | Media (6.1) | 0.28% | — | Wpwebelite Woocommerce PDF Vouchers | 31/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Wpwebelite Woocommerce PDF Vouchers | 18/12/2024 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers woocommerce-pdf-vouchers allows Privilege Escalation.This issue affects WooCommerce PDF Vouchers: from n/a through < 4.9.9. |