Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
113 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.60% | — | Royal-elementor-addons Royal Elementor Addons | 10/1/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration… | |
| Modificada | Alta (8.1) | 0.79% | — | Royal-elementor-addons Royal Elementor Addons | 10/1/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates… | |
| Modificada | Alta (8.1) | 0.94% | — | Royal-elementor-addons Royal Elementor Addons | 10/1/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data. | |
| Modificada | Media (6.5) | 0.79% | — | Royal-elementor-addons Royal Elementor Addons | 10/1/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it… | |
| Modificada | Alta (8.8) | 0.75% | — | Royal-elementor-addons Royal Elementor Addons | 10/1/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7',… | |
| Modificada | Alta (8.8) | 0.81% | — | Royal-elementor-addons Royal Elementor Addons | 10/1/2023 | 17/6/2026 | The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If… | |
| Modificada | Media (4.3) | 0.26% | — | Royal-elementor-addons Royal Elementor Addons | 9/1/2023 | 17/6/2026 | The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title | |
| Modificada | Baja (3.1) | 0.25% | — | Royal-elementor-addons Royal Elementor Addons | 9/1/2023 | 17/6/2026 | The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug. | |
| Modificada | Alta (8.8) | 2.7% | — | Royalapps Royal TS | 9/6/2020 | 17/6/2026 | Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach. | |
| Modificada | Media (6.1) | 1.2% | — | Royal-slider Project Royal-slider | 26/9/2019 | 17/6/2026 | The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter. | |
| Modificada | Alta (8.1) | 8.0% | 💥 Exploit | Royalapplications Royal TSRoyalapplications Royal TSX | 20/11/2018 | 17/6/2026 | The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure. | |
| Modificada | Alta (7.5) | 1.1% | — | Royalclassiccoin Project Royalclassiccoin | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for RoyalClassicCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Baja (2.1) | 0.32% | — | Royal Davinci | 1/1/1999 | 16/6/2026 | PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access. |