Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
199 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.92% | 💥 PoC | Oretnom23 Packers AND Movers Management System | 24/10/2024 | 17/6/2026 | A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id | |
| Modificada | Media (5.4) | 0.26% | — | Moveaddons Move Addons FOR Elementor | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through <= 1.3.4. | |
| Modificada | Media (5.4) | 0.28% | — | Moveaddons Move Addons FOR Elementor | 1/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor move-addons allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through <= 1.3.3. | |
| Analizada | Crítica (9.8) | 0.62% | — | Progress Moveit Transfer | 29/7/2024 | 17/6/2026 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3. | |
| Analizada | Crítica (9.8) | 81% | 💥 PoC | Progress Moveit Transfer | 25/6/2024 | 17/6/2026 | Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2. | |
| Modificada | Crítica (9.1) | 6.8% | — | Progress Moveit Gateway | 25/6/2024 | 17/6/2026 | Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0. | |
| Modificada | Alta (7.5) | 2.5% | — | Microsoft Azure Storage Data Movement Library | 11/6/2024 | 20/7/2026 | Azure Storage Movement Client Library Denial of Service Vulnerability | |
| Modificada | Alta (8.8) | 1.4% | 💥 PoC | Xlplugins Nextmove | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0. | |
| Modificada | Alta (7.3) | 0.28% | — | Moveaddons Move Addons FOR Elementor | 4/6/2024 | 17/6/2026 | Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9. | |
| Analizada | Alta (7.5) | 0.24% | — | Progress Moveit Automation | 22/5/2024 | 17/6/2026 | The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length. | |
| Modificada | Media (5.4) | 0.35% | — | Moveaddons Move Addons FOR Elementor | 21/5/2024 | 17/6/2026 | The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.4) | 0.29% | — | Visual Footer Credit RemoverAI | 14/5/2024 | 17/6/2026 | The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to… | |
| Modificada | Media (5.4) | 0.25% | — | Moveaddons Move Addons FOR Elementor | 8/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.0. | |
| Aplazada | Media (4.3) | 0.43% | — | Admin BAR RemoverAI | 2/5/2024 | 17/6/2026 | The Admin Bar Remover plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_form() function in all versions up to, and including, 1.0.2.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to enable or disable… | |
| Aplazada | Alta (8.6) | 0.53% | — | Skymoonlabs MovetoAI | 16/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Skymoon Labs MoveTo.This issue affects MoveTo: from n/a through 6.2. | |
| Modificada | Media (4.3) | 0.75% | 💥 PoC | Xlplugins Nextmove | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.18.1. | |
| Modificada | Media (4.8) | 0.34% | — | Wpchill Remove Footer Credit | 15/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Footer Credit allows Stored XSS.This issue affects Remove Footer Credit: from n/a through 1.0.13. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Skymoonlabs MovetoAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. | |
| Modificada | Alta (7.5) | 0.51% | — | Joelhardi User Spam Remover | 10/4/2024 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0. | |
| Modificada | Media (5.4) | 0.29% | — | Moveaddons Move Addons FOR Elementor | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.2.9. | |
| Modificada | Media (5.4) | 0.34% | — | Moveaddons Move Addons FOR Elementor | 23/3/2024 | 17/6/2026 | The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up to, and including, 1.2.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.39% | — | Progress Moveit Transfer | 20/3/2024 | 17/6/2026 | In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user… | |
| Aplazada | Alta (8.1) | 0.62% | 💥 PoC | Easeus MobimoverAI | 7/3/2024 | 17/6/2026 | Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory. | |
| Modificada | Media (5.3) | 0.53% | — | Xlplugins FinaleXlplugins Nextmove | 1/3/2024 | 17/6/2026 | The NextMove Lite – Thank You Page for WooCommerce and Finale Lite – Sales Countdown Timer & Discount for WooCommerce plugins for WordPress are vulnerable to unauthorized access of data due to a missing capability check on the download_tools_settings() function in all versions up to, and including, 2.17.0. This makes… | |
| Modificada | Crítica (9.8) | 0.56% | — | Skymoonlabs Moveto | 28/2/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2. |