Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.27% | — | Theeventprime Eventprime | 10/10/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Metagauss EventPrime eventprime-event-calendar-management.This issue affects EventPrime: from n/a through <= 4.0.4.5. | |
| Analizada | Media (5.3) | 0.35% | — | Metagauss Eventprime | 10/9/2024 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization checks in all versions up to, and including, 4.0.4.3. This makes it possible for unauthenticated attackers to view private or… | |
| Analizada | Media (5.4) | 0.15% | — | Intel High Level Synthesis CompilerIntel Oneapi Dpc++/c++ CompilerIntel Quartus Prime | 14/8/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.4) | 0.15% | — | Intel Quartus Prime | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 0.47% | — | Metagauss Eventprime | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.4. | |
| Modificada | Media (5.4) | 0.32% | — | Bdthemes Prime Slider | 7/6/2024 | 17/6/2026 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ attribute within the Pacific widget in all versions up to, and including, 3.14.7 due to insufficient input sanitization and output escaping.… | |
| Modificada | Media (5.4) | 0.26% | — | Bdthemes Prime Slider | 23/5/2024 | 17/6/2026 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pagepiling widget in all versions up to, and including, 3.14.1 due to insufficient input sanitization and output escaping on user supplied… | |
| Analizada | Alta (7.8) | 0.96% | — | Avira Prime | 22/5/2024 | 17/6/2026 | Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The… | |
| Analizada | Media (5.3) | 0.52% | — | Metagauss Eventprime | 17/5/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss EventPrime allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EventPrime: from n/a through 2.8.6. | |
| Analizada | Alta (7.3) | 0.18% | — | Intel Quartus Prime | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.3) | 0.18% | — | Intel Quartus Prime | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.3) | 0.20% | — | Intel Quartus Prime | 16/5/2024 | 17/6/2026 | Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.3) | 0.20% | — | Intel Quartus Prime | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.34% | — | Bdthemes Prime Slider | 14/5/2024 | 17/6/2026 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.51% | — | Bdthemes Prime Slider | 22/4/2024 | 17/6/2026 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2. | |
| Modificada | Alta (8.8) | 0.40% | — | Bdthemes Prime Slider | 22/4/2024 | 17/6/2026 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2. | |
| Modificada | Media (5.4) | 0.34% | — | Bdthemes Prime Slider | 20/4/2024 | 17/6/2026 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via urls in link fields, images from URLs, and html tags used in widgets in all versions up to,… | |
| Modificada | Media (4.3) | 0.35% | — | Bdthemes Prime Slider | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.11.10. | |
| Modificada | Media (4.8) | 0.36% | — | Metagauss Eventprime | 27/3/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. | |
| Modificada | Media (5.4) | 0.35% | — | Bdthemes Prime Slider | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.1. | |
| Modificada | Alta (7.5) | 0.44% | — | Metagauss Eventprime | 23/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. | |
| Modificada | Media (5.3) | 0.26% | — | Metagauss Eventprime | 13/3/2024 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin allowing unauthenticated users to update the status of order payments. This makes it possible for unauthenticated attackers to book events… | |
| Modificada | Media (4.3) | 0.53% | — | Metagauss Eventprime | 13/3/2024 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the booking_export_all() function in all versions up to, and including, 3.4.1. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Modificada | Media (4.3) | 0.44% | — | Metagauss Eventprime | 13/3/2024 | 17/6/2026 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_attendees_email_by_event_id() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.34% | — | Bdthemes Prime Slider | 13/3/2024 | 17/6/2026 | The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'settings['title_tags']' attribute of the Mercury widget in all versions up to, and including, 3.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… |