Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

113 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.60%—Royal-elementor-addons Royal Elementor Addons10/1/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_final_settings_setup' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to finalize activation of preset site configuration…
ModificadaAlta (8.1)0.79%—Royal-elementor-addons Royal Elementor Addons10/1/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_import_templates_kit' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to import preset site configuration templates…
ModificadaAlta (8.1)0.94%—Royal-elementor-addons Royal Elementor Addons10/1/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_reset_previous_import' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to reset previously imported data.
ModificadaMedia (6.5)0.79%—Royal-elementor-addons Royal Elementor Addons10/1/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_fix_royal_compatibility' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to deactivate every plugin on the site unless it…
ModificadaAlta (8.8)0.75%—Royal-elementor-addons Royal Elementor Addons10/1/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_plugins' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'contact-form-7',…
ModificadaAlta (8.8)0.81%—Royal-elementor-addons Royal Elementor Addons10/1/202317/6/2026
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in the 'wpr_activate_required_theme' AJAX action in versions up to, and including, 1.3.59. This allows any authenticated user, including those with subscriber-level permissions, to activate the 'royal-elementor-kit' theme. If…
ModificadaMedia (4.3)0.26%—Royal-elementor-addons Royal Elementor Addons9/1/202317/6/2026
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorisation and CSRF checks when creating a template, and does not ensure that the post created is a template. This could allow any authenticated users, such as subscriber to create a post (as well as any post type) with an arbitrary title
ModificadaBaja (3.1)0.25%—Royal-elementor-addons Royal Elementor Addons9/1/202317/6/2026
The Royal Elementor Addons WordPress plugin before 1.3.56 does not have authorization and CSRF checks when deleting a template and does not ensure that the post to be deleted is a template. This could allow any authenticated users, such as subscribers, to delete arbitrary posts assuming they know the related slug.
ModificadaAlta (8.8)2.7%—Royalapps Royal TS9/6/202017/6/2026
Royal TS before 5 has a 0.0.0.0 listener, which makes it easier for attackers to bypass tunnel authentication via a brute-force approach.
ModificadaMedia (6.1)1.2%—Royal-slider Project Royal-slider26/9/201917/6/2026
The Royal-Slider plugin before 3.2.7 for WordPress has XSS via the rstype parameter.
ModificadaAlta (8.1)8.0%💥 ExploitRoyalapplications Royal TSRoyalapplications Royal TSX20/11/201817/6/2026
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure.
ModificadaAlta (7.5)1.1%—Royalclassiccoin Project Royalclassiccoin9/7/201817/6/2026
The mintToken function of a smart contract implementation for RoyalClassicCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaBaja (2.1)0.32%—Royal Davinci1/1/199916/6/2026
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.
Orbitaley — Vulnerabilidades