Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1431 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.19%—Schneider-electric Easergy Builder Installer18/4/202317/6/2026
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected…
ModificadaMedia (6.1)0.41%—Reputeinfosystems Arforms Form Builder18/4/202317/6/2026
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions.
ModificadaMedia (6.5)0.90%—Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder17/4/202317/6/2026
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks
ModificadaMedia (5.4)0.44%—Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder17/4/202317/6/2026
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored…
ModificadaMedia (6.5)0.40%—Jenkins Consul KV Builder12/4/202317/6/2026
Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.
ModificadaMedia (4.3)0.32%—Jenkins Consul KV Builder12/4/202317/6/2026
Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
ModificadaMedia (5.3)0.52%—Jenkins Assembla Merge Request Builder12/4/202317/6/2026
A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
ModificadaAlta (7.5)0.63%—Dpgaspar Flask-appbuilder10/4/202317/6/2026
Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and setting an `AUTH_RATE_LIMIT`.
ModificadaMedia (5.4)0.38%—Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.
ModificadaMedia (5.4)0.47%—Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder3/4/202317/6/2026
The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.38%—Webdevocean Image Hover Effects FOR Wpbakery Page Builder30/3/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
ModificadaMedia (4.8)0.37%—Wpmart Interactive SVG Image MAP Builder28/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions.
ModificadaAlta (7.8)1.9%💥 PoCLinux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+927/3/202317/6/2026
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
ModificadaMedia (6.5)0.50%—Strategy11 Formidable Form Builder27/3/202317/6/2026
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections.
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaMedia (5.4)0.44%—Campaign URL Builder Project Campaign URL Builder13/3/202317/6/2026
The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaCrítica (9.8)3.9%💥 Exploit10web MAP Builder FOR Google Maps13/3/202317/6/2026
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
ModificadaAlta (8.8)0.27%—Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
ModificadaBaja (3.7)0.46%—Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+312/3/202317/6/2026
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack.
AnalizadaAlta (8.8)1.6%⚠ Explotación activaWebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+196/3/20238/10/2026
A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues.
ModificadaMedia (5.4)0.44%—Resumebuilder Resume Builder6/3/202317/6/2026
The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users
ModificadaMedia (6.1)29%💥 ExploitWpmet Metform Elementor Contact Form Builder2/3/202317/6/2026
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
ModificadaMedia (5.3)0.69%—Wpmet Metform Elementor Contact Form Builder2/3/202317/6/2026
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha…
ModificadaMedia (5.4)0.23%—Hasthemes Woolentor - Woocommerce Elementor Addons + Builder1/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change.
ModificadaAlta (8.8)0.26%—Strategy11 Formidable Form Builder28/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions.