Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | Mitel 6869i SIP Firmware | 9/6/2024 | 17/6/2026 | On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution. | |
| Modificada | Alta (8.8) | 3.2% | — | Mitel 6869i SIP Firmware | 9/6/2024 | 17/6/2026 | An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is… | |
| Modificada | Alta (8.8) | 0.39% | — | Unlimited-elements Unlimited Elements FOR Elementor | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65. | |
| Modificada | Alta (8.8) | 0.51% | — | Unlimited-elements Unlimited Elements FOR Elementor | 6/6/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions up to, and including, 1.5.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Modificada | Alta (8.8) | 0.37% | — | Unlimited-elements Unlimited Elements FOR Elementor | 5/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.109. | |
| Aplazada | Crítica (10) | 88% | 💥 Exploit | Codeer Limited Bricks BuilderAI | 4/6/2024 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Codeer Limited Bricks Builder allows Code Injection.This issue affects Bricks Builder: from n/a through 1.9.6. | |
| Analizada | Alta (7.2) | 0.52% | — | Unlimited-elements Unlimited Elements FOR Elementor | 4/6/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66. | |
| Modificada | Media (4.6) | 0.26% | — | Unlimited-elements Unlimited Elements FOR Elementor | 30/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text field widget in all versions up to, and including, 1.5.107 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Analizada | Media (5.4) | 0.25% | — | Mitel Micontact Center Business | 29/5/2024 | 17/6/2026 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient input validation. | |
| Analizada | Media (6.1) | 0.26% | — | Mitel Micontact Center Business | 29/5/2024 | 17/6/2026 | A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to conduct a stored cross-site scripting (XSS) attack due to insufficient input validation. | |
| Modificada | Alta (8.8) | 1.3% | — | Unlimited-elements Unlimited Elements FOR Elementor | 29/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with contributor access and above, to execute code… | |
| Modificada | Alta (8.8) | 0.45% | — | Unlimited-elements Unlimited Elements FOR Elementor | 23/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up to, and including, 1.5.107 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… | |
| Aplazada | Alta (7.8) | 0.14% | — | Terabyte Unlimited Image FOR WindowsAI | 21/5/2024 | 17/6/2026 | An issue in TeraByte Unlimited Image for Windows v.3.64.0.0 and before and fixed in v.4.0.0.0 allows a local attacker to escalate privileges via the TBOFLHelper64.sys and TBOFLHelper.sys component. | |
| Aplazada | Media (4.2) | 0.37% | — | Delimited File Connector Cloud ConnectorAI | 15/5/2024 | 17/6/2026 | A file path traversal vulnerability was identified in the DelimitedFileConnector Cloud Connector that allowed an authenticated administrator to set arbitrary connector attributes, including the “file“ attribute, which in turn allowed the user to access files uploaded for other sources. | |
| Modificada | Media (6.1) | 0.40% | — | Unlimited-elements Unlimited Elements FOR Elementor | 14/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Alta (8.8) | 0.82% | — | Unlimited-elements Unlimited Elements FOR Elementor | 14/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.5.102 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL… | |
| Modificada | Alta (7.2) | 1.7% | — | Unlimited-elements Unlimited Elements FOR Elementor | 14/5/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it possible for… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Mitel 6800 Series SIP PhoneAIMitel 6900 Series SIP PhoneAIMitel 6900w Series SIP PhoneAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an unauthorized access attack due to improper access control. A successful exploit could allow an attacker… | |
| Aplazada | Media (6.2) | 0.44% | — | Mitel 6800 Series SIP PhoneAIMitel 6900 Series SIP PhoneAIMitel 6900w Series SIP PhoneAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct an argument injection attack due to insufficient parameter sanitization. A… | |
| Aplazada | Media (4.2) | 0.24% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker with administrative privilege to conduct a path traversal attack due to insufficient input validation. A successful… | |
| Aplazada | Alta (7.5) | 0.62% | 💥 PoC | Mitel 6800 Series SIP PhoneAIMitel 6900 Series SIP PhoneAIMitel 6900w Series SIP PhoneAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an unauthenticated attacker to conduct an authentication bypass attack due to improper authentication control. A successful exploit could allow an… | |
| Aplazada | Media (6.4) | 0.25% | — | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 2/5/2024 | 17/6/2026 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 Conference Unit through 5.1.1 SP8 allows an authenticated attacker to conduct a buffer overflow attack due to insufficient bounds checking and input sanitization. A successful exploit… | |
| Aplazada | Alta (7.5) | 0.75% | — | TVS Motor Company Limited TVS ConnetAI | 30/4/2024 | 17/6/2026 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information via an insecure API endpoint. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |
| Aplazada | Crítica (9.1) | 0.65% | — | TVS Motor Company Limited TVS ConnetAIGoogle AndroidAIApple IOSAI | 30/4/2024 | 17/6/2026 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact Feature. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |
| Modificada | Alta (8.8) | 0.76% | — | Unlimited-elements Unlimited Elements FOR Elementor | 24/4/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Upload a Web Shell to a Web Server.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.60. |