Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.19% | — | Schneider-electric Easergy Builder Installer | 18/4/2023 | 17/6/2026 | A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected… | |
| Modificada | Media (6.1) | 0.41% | — | Reputeinfosystems Arforms Form Builder | 18/4/2023 | 17/6/2026 | Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARForms Form Builder plugin <= 1.5.5 versions. | |
| Modificada | Media (6.5) | 0.90% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate some shortcode attributes before using them to generate paths passed to include function/s, allowing any authenticated users such as subscriber to perform LFI attacks | |
| Modificada | Media (5.4) | 0.44% | — | Pricing Tables FOR Wpbakery Page Builder Project Pricing Tables FOR Wpbakery Page Builder | 17/4/2023 | 17/6/2026 | The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored… | |
| Modificada | Media (6.5) | 0.40% | — | Jenkins Consul KV Builder | 12/4/2023 | 17/6/2026 | Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it. | |
| Modificada | Media (4.3) | 0.32% | — | Jenkins Consul KV Builder | 12/4/2023 | 17/6/2026 | Jenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. | |
| Modificada | Media (5.3) | 0.52% | — | Jenkins Assembla Merge Request Builder | 12/4/2023 | 17/6/2026 | A missing permission check in Jenkins Assembla merge request builder Plugin 1.1.13 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository. | |
| Modificada | Alta (7.5) | 0.63% | — | Dpgaspar Flask-appbuilder | 10/4/2023 | 17/6/2026 | Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and setting an `AUTH_RATE_LIMIT`. | |
| Modificada | Media (5.4) | 0.38% | — | Material Design Icons FOR Page Builders Project Material Design Icons FOR Page Builders | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Image Over Image FOR Wpbakery Page Builder Project Image Over Image FOR Wpbakery Page Builder | 3/4/2023 | 17/6/2026 | The Image Over Image For WPBakery Page Builder WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.38% | — | Webdevocean Image Hover Effects FOR Wpbakery Page Builder | 30/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Wpmart Interactive SVG Image MAP Builder | 28/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Mehjabin Orthi Interactive SVG Image Map Builder plugin <= 1.0 versions. | |
| Modificada | Alta (7.8) | 1.9% | 💥 PoC | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+9 | 27/3/2023 | 17/6/2026 | A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution. | |
| Modificada | Media (6.5) | 0.50% | — | Strategy11 Formidable Form Builder | 27/3/2023 | 17/6/2026 | The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to determine the IP address of the client, leading to IP Address spoofing and bypass of anti-spam protections. | |
| Modificada | Media (4.3) | 0.28% | — | Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 27/3/2023 | 17/6/2026 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Media (5.4) | 0.44% | — | Campaign URL Builder Project Campaign URL Builder | 13/3/2023 | 17/6/2026 | The Campaign URL Builder WordPress plugin before 1.8.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Crítica (9.8) | 3.9% | 💥 Exploit | 10web MAP Builder FOR Google Maps | 13/3/2023 | 17/6/2026 | The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | |
| Modificada | Alta (8.8) | 0.27% | — | Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder | 13/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions. | |
| Modificada | Baja (3.7) | 0.46% | — | Ibexa CommerceIbexa Digital Experience PlatformIbexa EZ PlatformIbexa Ezplatform-page-builder+3 | 12/3/2023 | 17/6/2026 | An issue was discovered in eZ Platform Ibexa Kernel before 1.3.19. It allows determining account existence via a timing attack. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa | WebkitgtkWpewebkit WPE WebkitRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUS+19 | 6/3/2023 | 8/10/2026 | A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution. Improved memory handling addresses the multiple memory corruption issues. | |
| Modificada | Media (5.4) | 0.44% | — | Resumebuilder Resume Builder | 6/3/2023 | 17/6/2026 | The Resume Builder WordPress plugin through 3.1.1 does not sanitize and escape some parameters related to Resume, which could allow users with a role as low as subscriber to perform Stored XSS attacks against higher privilege users | |
| Modificada | Media (6.1) | 29% | 💥 Exploit | Wpmet Metform Elementor Contact Form Builder | 2/3/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts… | |
| Modificada | Media (5.3) | 0.69% | — | Wpmet Metform Elementor Contact Form Builder | 2/3/2023 | 17/6/2026 | The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and including, 3.2.1. This is due to insufficient server side checking on the captcha value submitted during a form submission. This makes it possible for unauthenticated attackers to bypass Captcha… | |
| Modificada | Media (5.4) | 0.23% | — | Hasthemes Woolentor - Woocommerce Elementor Addons + Builder | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HasThemes ShopLentor plugin <= 2.5.1 leading to plugin settings change. | |
| Modificada | Alta (8.8) | 0.26% | — | Strategy11 Formidable Form Builder | 28/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Form Builder Team Formidable Forms plugin <= 5.5.6 versions. |