Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
390 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.50% | — | Codeastrology Ultraaddons | 21/11/2024 | 17/6/2026 | The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.8 via the show_template due to missing validation on a user… | |
| Aplazada | Crítica (10) | 3.1% | — | Cisco Unified Industrial Wireless SoftwareAICisco Ultra Reliable Wireless BackhaulAI | 6/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injection attacks with root privileges on the underlying operating system. This… | |
| Aplazada | Media (6.5) | 0.27% | — | Saiful Islam Ultraaddons Elementor LiteAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite allows Stored XSS.This issue affects UltraAddons Elementor Lite: from n/a through <= 2.0.2. | |
| Aplazada | Alta (7.5) | 0.56% | — | Expresstechsystems WP Ticket UltraAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a through <= 1.0.5. | |
| Modificada | Alta (8.8) | 0.62% | — | Ultrapress | 1/10/2024 | 17/6/2026 | The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the… | |
| Analizada | Alta (8.8) | 0.63% | — | Ultrapress Empowerment | 1/10/2024 | 17/6/2026 | The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the… | |
| Analizada | Alta (8.8) | 0.63% | — | Ultrapress Unseen Blog | 1/10/2024 | 17/6/2026 | The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject a PHP Object. No known POP chain is present in the… | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Aplazada | Alta (7.3) | 0.24% | — | Intel Core Ultra ProcessorAI | 14/8/2024 | 17/6/2026 | Improper isolation in the Intel(R) Core(TM) Ultra Processor stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.32% | — | Booking Ultra PROAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Ultra Pro allows Stored XSS.This issue affects Booking Ultra Pro: from n/a through 1.1.13. | |
| Aplazada | Media (5.4) | 0.30% | — | Bookingultrapro Appointments Booking CalendarAI | 18/7/2024 | 17/6/2026 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the multiple functions called via AJAX like save_fields_settings, bup_delete_user_avatar, bup_crop_avatar_user_profile_image, and more in all versions… | |
| Aplazada | Alta (7.1) | 0.45% | — | Booking Ultra PROAI | 12/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Booking Ultra Pro allows PHP Local File Inclusion.This issue affects Booking Ultra Pro: from n/a through 1.1.13. | |
| Modificada | Media (5.4) | 0.36% | — | Codeastrology Ultraaddons | 10/7/2024 | 17/6/2026 | The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output… | |
| Modificada | Media (5.4) | 0.24% | — | Codeastrology Ultraaddons | 6/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saiful Islam UltraAddons Elementor Lite ultraaddons-elementor-lite allows DOM-Based XSS.This issue affects UltraAddons Elementor Lite: from n/a through <= 2.0.2. | |
| Modificada | Media (6.7) | 0.15% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+384 | 2/7/2024 | 17/6/2026 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges | |
| Modificada | Alta (8.8) | 0.44% | — | Themify Ultra | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | |
| Modificada | Alta (8.8) | 0.36% | — | Themify Ultra | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Themify Themify Ultra.This issue affects Themify Ultra: from n/a through 7.3.5. | |
| Aplazada | Alta (8.8) | 0.45% | — | Booking Ultra PROAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Booking Ultra Pro allows Privilege Escalation.This issue affects Booking Ultra Pro: from n/a through 1.1.12. | |
| Analizada | Alta (8.8) | 0.57% | — | Themify Ultra | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5. | |
| Aplazada | Media (4.7) | 0.28% | — | Intel Core Ultra ProcessorsAI | 16/5/2024 | 17/6/2026 | Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Alta (8.4) | 0.84% | — | Gehealthcare Ultrasound DevicesAI | 14/5/2024 | 17/6/2026 | OS command injection vulnerabilities in GE HealthCare ultrasound devices | |
| Aplazada | Alta (7.4) | 0.20% | — | Gehealthcare UltrasoundAI | 14/5/2024 | 17/6/2026 | Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices | |
| Analizada | Media (4.4) | 0.18% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+264 | 10/4/2024 | 17/6/2026 | Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Media (4.9) | 0.49% | — | Dell Precision 3430 Tower FirmwareDell Precision 3431 Tower FirmwareDell Precision 3630 Tower FirmwareDell Precision 5820 Tower Firmware+169 | 1/3/2024 | 17/6/2026 | Dell Platform BIOS contains an Improper Null Termination vulnerability. A high privilege user with network access to the system could potentially send malicious data to the device in order to cause some services to cease to function. | |
| Modificada | Baja (3.3) | 0.10% | — | AMD Alveo U50 FirmwareAMD Alveo U200 FirmwareAMD Alveo U250 FirmwareAMD Alveo U280 Firmware+43 | 13/2/2024 | 17/6/2026 | Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams. |