Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

199 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.92%💥 PoCOretnom23 Packers AND Movers Management System24/10/202417/6/2026
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
ModificadaMedia (5.4)0.26%—Moveaddons Move Addons FOR Elementor6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through <= 1.3.4.
ModificadaMedia (5.4)0.28%—Moveaddons Move Addons FOR Elementor1/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through <= 1.3.3.
AnalizadaCrítica (9.8)0.62%—Progress Moveit Transfer29/7/202417/6/2026
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.
AnalizadaCrítica (9.8)81%💥 PoCProgress Moveit Transfer25/6/202417/6/2026
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2.
ModificadaCrítica (9.1)6.8%—Progress Moveit Gateway25/6/202417/6/2026
Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.
ModificadaAlta (7.5)2.5%—Microsoft Azure Storage Data Movement Library11/6/202420/7/2026
Azure Storage Movement Client Library Denial of Service Vulnerability
ModificadaAlta (8.8)1.4%💥 PoCXlplugins Nextmove9/6/202417/6/2026
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.
ModificadaAlta (7.3)0.28%—Moveaddons Move Addons FOR Elementor4/6/202417/6/2026
Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.
AnalizadaAlta (7.5)0.24%—Progress Moveit Automation22/5/202417/6/2026
The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.
ModificadaMedia (5.4)0.35%—Moveaddons Move Addons FOR Elementor21/5/202417/6/2026
The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.4)0.29%—Visual Footer Credit RemoverAI14/5/202417/6/2026
The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to…
ModificadaMedia (5.4)0.25%—Moveaddons Move Addons FOR Elementor8/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.0.
AplazadaMedia (4.3)0.43%—Admin BAR RemoverAI2/5/202417/6/2026
The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_form() function in all versions up to, and including, 1.0.2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable or disable…
AplazadaAlta (8.6)0.53%—Skymoonlabs MovetoAI16/4/202417/6/2026
Missing Authorization vulnerability in Skymoon Labs MoveTo.This issue affects MoveTo: from n/a through 6.2.
ModificadaMedia (4.3)0.75%💥 PoCXlplugins Nextmove15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1.
ModificadaMedia (4.8)0.34%—Wpchill Remove Footer Credit15/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from n/a through 1.0.13.
AplazadaCrítica (9.8)0.58%—Skymoonlabs MovetoAI11/4/202417/6/2026
Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
ModificadaAlta (7.5)0.51%—Joelhardi User Spam Remover10/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.
ModificadaMedia (5.4)0.29%—Moveaddons Move Addons FOR Elementor27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.2.9.
ModificadaMedia (5.4)0.34%—Moveaddons Move Addons FOR Elementor23/3/202417/6/2026
The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AnalizadaMedia (4.3)0.39%—Progress Moveit Transfer20/3/202417/6/2026
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user…
AplazadaAlta (8.1)0.62%💥 PoCEaseus MobimoverAI7/3/202417/6/2026
Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.
ModificadaMedia (5.3)0.53%—Xlplugins FinaleXlplugins Nextmove1/3/202417/6/2026
The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes…
ModificadaCrítica (9.8)0.56%—Skymoonlabs Moveto28/2/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.
Orbitaley — Vulnerabilidades