Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

299 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.7)0.21%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow an authenticated attacker with administrative privilege to conduct a privilege escalation attack due to the execution of a resource with unnecessary privileges. A successful exploit could allow an…
AnalizadaCrítica (9.8)66%💥 ExploitMitel Micollab21/10/202417/6/2026
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access sensitive information and execute arbitrary database and management…
AnalizadaCrítica (9.8)1.3%—Mitel Micollab21/10/202417/6/2026
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.
ModificadaMedia (4.8)0.32%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit could allow an attacker to…
ModificadaMedia (4.8)0.32%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a Stored Cross-Site Scripting (XSS) attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute…
AnalizadaAlta (7.2)0.41%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the web conferencing component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary database and…
ModificadaAlta (7.2)0.41%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the Suite Applications Services component of Mitel MiCollab through 9.7.1.110 could allow an authenticated attacker with administrative privileges to conduct a SQL Injection attack due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary…
AnalizadaAlta (8.2)0.38%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the AWV (Audio, Web, and Video) Conferencing component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to perform unauthorized data-access attacks due to missing authentication mechanisms. A successful exploit could allow an attacker to access and delete…
AnalizadaCrítica (9.4)0.48%—Mitel Micollab21/10/202417/6/2026
A vulnerability in the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a SQL injection attack due to insufficient sanitization of user input. A successful exploit could allow an attacker to access non-sensitive user…
AnalizadaAlta (7.7)0.42%—Mitel Micollab21/10/202417/6/2026
The API Interface of the AWV (Audio, Web and Video Conferencing) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct SQL injection due to insufficient sanitization of user input. A successful exploit could allow an attacker with knowledge of specific details…
AplazadaMedia (6.5)0.27%—Nayon46 Unlimited Addon FOR ElementorAI16/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nayon46 Unlimited Addon For Elementor unlimited-addon-for-elementor allows Stored XSS.This issue affects Unlimited Addon For Elementor: from n/a through <= 2.0.0.
ModificadaAlta (7.2)1.1%—Unlimited-elements Unlimited Elements FOR Elementor16/10/202417/6/2026
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.121.
AplazadaMedia (5.3)0.49%—D-zero CO LTD BurgereditorAID-zero CO LTD Burgereditor Limited EditionAIBasercmsAI11/10/20245/7/2026
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and BurgerEditor Limited Edition before 2.25.1 allows remote attackers to obtain sensitive information by exposing a list of the uploaded files.
ModificadaMedia (6.1)0.33%—Unlimited-elements Unlimited Elements FOR Elementor6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,…
AnalizadaAlta (8.1)0.45%—Mitel Micontact Center Business1/10/202417/6/2026
A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack due to inadequate access control checks. A successful exploit requires user interaction and could allow an attacker to access sensitive…
AplazadaMedia (6.8)0.55%—Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI13/8/202417/6/2026
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an unauthenticated attacker with physical access to the phone to conduct an argument injection attack, due to insufficient parameter sanitization. A…
ModificadaAlta (8.8)0.49%—Mitel Mivoice Mx-one13/8/202417/6/2026
The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper access control. A successful exploit could allow an attacker to bypass the authorization schema.
AnalizadaAlta (7.2)42%⚠ Explotación activaMitel 6970 FirmwareMitel 6940w SIP FirmwareMitel 6930w SIP FirmwareMitel 6920w SIP Firmware+1112/8/202417/6/2026
A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot…
ModificadaMedia (5.3)0.25%—Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates)9/7/202417/6/2026
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible…
ModificadaMedia (5.4)0.47%—Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates)9/7/202417/6/2026
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
ModificadaMedia (5.4)0.51%—Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates)9/7/202417/6/2026
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
ModificadaAlta (8.8)0.50%—Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates)9/7/202417/6/2026
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
AplazadaBaja (3.5)0.27%—Kodezen Limited Academy LMSAI6/7/202417/6/2026
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.
AplazadaCrítica (9.8)0.71%—Daemon PTY Limited Farcry CoreAI25/6/202417/6/2026
An arbitrary file upload vulnerability in /fileupload/upload.cfm in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to execute arbitrary code via uploading a crafted .cfm file.
AplazadaMedia (5.9)0.22%—Daemon PTY Limited Farcry CoreAI25/6/202417/6/2026
An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.
Orbitaley — Vulnerabilidades