Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.36% | — | Appsbd Elite NotificationAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Appsbd Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification: from 1.5 through n/a. | |
| Aplazada | Alta (7.5) | 0.57% | — | Luvion Grand Elite 3 ConnectAI | 7/11/2024 | 17/6/2026 | An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These credentials can be obtained through an unauthenticated web request, e.g., for a JavaScript file. Also, the disclosed information includes the SSID and WPA2… | |
| Analizada | Alta (8.1) | 0.54% | — | Wpwebelite Woocommerce Social Login | 5/11/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to insufficient verification on the user being returned by the social login token. This makes it possible for unauthenticated attackers to log in as any existing user on… | |
| Analizada | Crítica (9.8) | 0.45% | — | Wpwebelite Woocommerce PDF Vouchers | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through 4.9.4. | |
| Analizada | Alta (8) | 0.91% | — | Autel Maxicharger AC Elite Business C50 Firmware | 28/9/2024 | 17/6/2026 | Autel MaxiCharger AC Elite Business C50 WebSocket Base64 Decoding Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 chargers. Although authentication is… | |
| Analizada | Alta (8) | 0.82% | — | Autel Maxicharger AC Elite Business C50 Firmware | 28/9/2024 | 17/6/2026 | Autel MaxiCharger AC Elite Business C50 BLE AppChargingControl Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Although authentication… | |
| Analizada | Alta (8.8) | 0.80% | — | Autel Maxicharger AC Elite Business C50 Firmware | 28/9/2024 | 17/6/2026 | Autel MaxiCharger AC Elite Business C50 BLE Hardcoded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.97% | — | Autel Maxicharger AC Elite Business C50 Firmware | 28/9/2024 | 17/6/2026 | Autel MaxiCharger AC Elite Business C50 DLB_HostHeartBeat Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 charging stations. Authentication is not… | |
| Analizada | Crítica (9.8) | 0.53% | — | Wpwebelite Docket | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPWeb Elite Docket (WooCommerce Collections / Wishlist / Watchlist) allows SQL Injection.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0. | |
| Analizada | Alta (8.8) | 0.53% | — | Autel Maxicharger AC Elite Business C50 Firmware | 21/8/2024 | 17/6/2026 | Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 EV chargers. Authentication is not… | |
| Analizada | Alta (7.5) | 0.48% | — | Wpwebelite Docket | 13/8/2024 | 17/6/2026 | Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections / Wishlist / Watchlist): from n/a before 1.7.0. | |
| Analizada | Crítica (9.3) | 0.50% | — | Wpwebelite Woocommerce PDF Vouchers | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5. | |
| Analizada | Crítica (9.8) | 0.61% | — | Wpwebelite Woocommerce Social Login | 12/8/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.5. This is due to the use of loose comparison of the activation code in the 'woo_slg_confirm_email_user' function. This makes it possible for unauthenticated attackers to log in as any… | |
| Analizada | Media (6.1) | 0.31% | — | Wpwebelite Woocommerce PDF Vouchers | 1/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Reflected XSS.This issue affects WooCommerce PDF Vouchers: from n/a before 4.9.5. | |
| Aplazada | Alta (7.3) | 0.40% | — | Wpwebelite Woocommerce PDF VouchersAI | 24/7/2024 | 17/6/2026 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient verification on the user being supplied during a QR code login through the plugin. This makes it possible for unauthenticated attackers to log in as any… | |
| Analizada | Alta (7.3) | 0.36% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthenticated privilege escalation in all versions up to, and including, 2.7.3. This is due to a lack of brute force controls on a weak one-time password. This makes it possible for unauthenticated attackers to brute force the one-time password for… | |
| Analizada | Crítica (9.8) | 0.52% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to change the default role to Administrator… | |
| Analizada | Alta (7.3) | 0.40% | — | Wpwebelite Woocommerce Social Login | 20/7/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.7.3. This is due to insufficient controls in the 'woo_slg_login_email' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, excluding an… | |
| Modificada | Alta (7.5) | 0.31% | — | Wpwebelite Woocommerce Social Login | 9/7/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in wpweb WooCommerce Social Login woo-social-login.This issue affects WooCommerce Social Login: from n/a through <= 2.6.3. | |
| Modificada | Media (6.1) | 0.31% | — | Pixelite Events Manager | 29/6/2024 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘country’ parameter in all versions up to, and including, 6.4.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Crítica (9.8) | 0.70% | — | Wpwebelite Woocommerce Social Login | 15/6/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of untrusted input from the 'woo_slg_verify' vulnerable parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is… | |
| Modificada | Media (5.3) | 0.31% | — | Wpwebelite Woocommerce Social Login | 15/6/2024 | 17/6/2026 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification. | |
| Modificada | Media (5.4) | 0.29% | — | Pixelite Events Manager | 12/6/2024 | 17/6/2026 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'event', 'location', and 'event_category' shortcodes in all versions up to, and including, 6.4.7.3 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Media (6.8) | 0.18% | — | HP Elite Slice FirmwareHP Elite Slice FOR Meeting Rooms FirmwareHP Elitebook 1040 G3 FirmwareHP Elitebook 820 G3 Firmware+22 | 10/6/2024 | 17/6/2026 | Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities. |