Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1956 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.25%—WP Basic Elements Project WP Basic Elements25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Damir Calusic WP Basic Elements plugin <= 5.2.15 versions.
ModificadaAlta (8.8)0.27%—Webmat Flexible Elementor Panel22/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WebMat Flexible Elementor Panel plugin <= 2.3.8 versions.
ModificadaMedia (4.8)0.39%—White Label Branding FOR Elementor Page Builder Project White Label Branding FOR Elementor Page Builder15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ozan Canakli White Label Branding for Elementor Page Builder plugin <= 1.0.2 versions.
ModificadaCrítica (9.8)76%💥 ExploitWpdeveloper Essential Addons FOR Elementor12/5/202317/6/2026
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
ModificadaAlta (7.8)0.15%—Intel NUC P14e Laptop Element10/5/202317/6/2026
Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.14%—Intel NUC 8 Compute Element Cm8i3cb4n FirmwareIntel NUC 8 Compute Element Cm8i5cb8n FirmwareIntel NUC 8 Compute Element Cm8i7cb8n FirmwareIntel NUC 8 Compute Element Cm8ccb4r Firmware+5510/5/202317/6/2026
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+3710/5/202317/6/2026
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.15%—Intel NUC P14e Laptop Element10/5/202317/6/2026
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel NUC P14e Laptop Element10/5/202317/6/2026
Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+3510/5/202317/6/2026
Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (5.4)0.44%—Topdigitaltrends Ultimate Carousel FOR Elementor8/5/202317/6/2026
The Ultimate Carousel For Elementor WordPress plugin through 2.1.7 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.8)1.5%—Crocoblock Jetengine FOR Elementor10/4/202317/6/2026
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
ModificadaAlta (7.8)0.43%—Wondershare Pdfelement4/4/202317/6/2026
An issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelement-pro_setup_full5239.exe file.
ModificadaMedia (4.8)0.39%—Unlimited-elements Unlimited Elements FOR Elementor28/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 1.5.48 versions.
ModificadaMedia (6.1)0.41%—Oxilab Image Hover Effects FOR Elementor With Lightbox AND Flipbox28/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in biplob018 Image Hover Effects for Elementor with Lightbox and Flipbox plugin <= 2.8 versions.
ModificadaMedia (4.3)0.26%—Hasthemes HT Slider FOR Elementor27/3/202317/6/2026
The HT Slider For Elementor WordPress plugin before 1.4.0 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaMedia (6.5)1.0%—Ooohboi Steroids FOR Elementor Project Ooohboi Steroids FOR Elementor27/3/202317/6/2026
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
ModificadaCrítica (9.8)0.68%—Varta Element Backup FirmwareVarta Element S1 FirmwareVarta Element S2 FirmwareVarta Element S3 Firmware+423/3/202317/6/2026
Hard-coded credentials in Web-UI of multiple VARTA Storage products in multiple versions allows an unauthorized attacker to gain administrative access to the Web-UI via network.
ModificadaCrítica (9.8)2.3%—Openbsd OpensshNetapp Brocade Fabric Operating SystemNetapp HCI Bootstrap OSNetapp Solidfire Element OS17/3/202314/7/2026
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
ModificadaMedia (5.4)0.47%—Themelocation Widgets FOR Woocommerce Products ON Elementor13/3/202317/6/2026
The Widgets for WooCommerce Products on Elementor WordPress plugin before 1.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…
ModificadaAlta (8.8)0.27%—Voidcoders Void Contact Form 7 Widget FOR Elementor Page Builder13/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
ModificadaMedia (6.5)0.80%—Posimyth THE Plus Addons FOR Elementor7/3/202317/6/2026
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin has a feature to add an "Info Box" to an Elementor created page. This Info Box can include an SVG image for the box. Unfortunately, the plugin used…
ModificadaAlta (8.8)0.89%—Posimyth THE Plus Addons FOR Elementor7/3/202317/6/2026
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default…
ModificadaAlta (8.8)1.5%—Envato ElementsEnvato Template KIT - Import7/3/202317/6/2026
The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads due to insufficient validation of file type upon extracting uploaded Zip files in the installFreeTemplateKit and uploadTemplateKitZipFile functions. This makes it possible for attackers with…