Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.28% | — | Wpindeed Ultimate Learning PROAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in azzaroco Ultimate Learning Pro indeed-learning-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ultimate Learning Pro: from n/a through <= 3.9.3. | |
| Aplazada | Media (4.3) | 0.12% | — | Rustaurius Ultimate FAQAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3. | |
| Aplazada | Media (4.3) | 0.23% | — | Ultimatemember ForumwpAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4. | |
| Aplazada | Media (6.5) | 0.24% | — | Wpmet WP Ultimate ReviewAI | 9/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Roxnor Wp Ultimate Review wp-ultimate-review allows DOM-Based XSS.This issue affects Wp Ultimate Review: from n/a through <= 2.3.7. | |
| Aplazada | Media (6.4) | 0.18% | — | Shortcodes UltimateAI | 23/11/2025 | 17/6/2026 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.4.5 via the su_shortcode_csv_table function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to… | |
| Aplazada | Media (5.3) | 0.24% | — | Ultimate Member Widgets FOR ElementorAI | 20/11/2025 | 17/6/2026 | The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the handle_filter_users function in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to extract partial… | |
| Aplazada | Media (4.3) | 0.21% | — | Wpswings Woocommerce Ultimate Points AND RewardsAI | 13/11/2025 | 7/10/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPSwings WooCommerce Ultimate Points And Rewards woocommerce-ultimate-points-and-rewards allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Ultimate Points And Rewards: from n/a through <= 2.10.2. | |
| Aplazada | Media (4.3) | 0.26% | — | WP Import Ultimate CSV XML ImporterAI | 12/11/2025 | 17/6/2026 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sensitive information due to a missing authorization check on the showsetting() function in all versions up to, and including, 7.33. This makes it possible for authenticated attackers, with Author-level… | |
| Analizada | Media (5.1) | 0.17% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'first_name' in '/clients/save_contact/'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/tickets/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'custom_field_1' in '/estimate_requests/save_estimate_request'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'reply_message' in '/messages/reply'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in '/events/save'. | |
| Analizada | Media (5.1) | 0.16% | — | Fairsketch Rise Ultimate Project Manager | 11/11/2025 | 17/6/2026 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection due to lack of proper validation of user inputs by sending a POST request in parameter 'title' in'/projects/save'. | |
| Modificada | Media (6.5) | 0.38% | — | Fairsketch Rise Ultimate Project Manager | 3/11/2025 | 5/7/2026 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user can append comments or upload attachments to tickets for which they lack view or edit authorization, due to missing authorization checks in the ticketing/commenting API. | |
| Analizada | Alta (8.7) | 0.41% | 💥 PoC | Ultimatefosters Ultimatepos | 3/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability exists in the administrative interface of ultimatefosters UltimatePOS 4.8 where input submitted in the purchase functionality is reflected without proper escaping in the admin log panel page in the 'reference No.' field. This flaw allows an authenticated attacker to execute… | |
| Aplazada | Media (6.5) | 0.17% | — | Brainstormforce Ultimate Addons FOR Wpbakery Page BuilderAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm_Force Ultimate Addons for WPBakery Page Builder ultimate_vc_addons allows Stored XSS.This issue affects Ultimate Addons for WPBakery Page Builder: from n/a through < 3.21.1. | |
| Aplazada | Media (6.5) | 0.18% | — | Themepoints TAB UltimateAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Tab Ultimate tabs-pro.This issue affects Tab Ultimate: from n/a through <= 1.8. | |
| Aplazada | Crítica (9.8) | 0.58% | — | Quantumcloud KBX PRO UltimateAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5. | |
| Aplazada | Media (6.5) | 0.22% | — | Dotcamp Ultimate BlocksAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows Stored XSS.This issue affects Ultimate Blocks: from n/a through <= 3.3.6. | |
| Analizada | Media (6.5) | 0.29% | — | Myupb Ultimate PHP Board | 16/10/2025 | 17/6/2026 | SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php. | |
| Analizada | Media (6.1) | 0.27% | — | Myupb Ultimate PHP Board | 16/10/2025 | 17/6/2026 | Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php. | |
| Aplazada | Media (6.4) | 0.29% | — | Ultimate Addons FOR WpbakeryAI | 16/10/2025 | 17/6/2026 | The Ultimate Addons for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to 3.21.1 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Alta (8.1) | 1.1% | 💥 PoC | Fairsketch Rise Ultimate Project Manager | 10/10/2025 | 5/7/2026 | Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into invoices and messages. Injected content renders in emails, PDFs, and messaging/chat modules sent to clients or team members, enabling phishing, credential theft, and business email compromise.… | |
| Aplazada | Media (4.3) | 0.18% | — | Brainstormforce Ultimate Addons FOR ElementorAI | 6/10/2025 | 17/6/2026 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) WordPress plugin before 2.5.0 does not sanitize SVG file contents when uploaded through the xmlrpc.php endpoint using base64 encode, leading to a Cross-Site Scripting vulnerability. |