Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
337 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.26% | — | Crocoblock Jetelements | 16/8/2024 | 17/6/2026 | The JetElements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'slide_id' parameters in all versions up to, and including, 2.6.20 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Analizada | Media (5.4) | 0.26% | — | Wpmet Elementskit | 15/8/2024 | 17/6/2026 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (4.3) | 0.35% | — | Wpmet Elementskit | 15/8/2024 | 17/6/2026 | The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'render_raw' function. This can allow authenticated attackers, with Contributor-level permissions and above, to extract sensitive data including private, future, and draft posts. | |
| Analizada | Alta (8.8) | 0.58% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 13/8/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Techeshta Card Elements FOR ElementorAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Techeshta Card Elements for Elementor allows Stored XSS.This issue affects Card Elements for Elementor: from n/a through 1.2.2. | |
| Aplazada | Baja (3.3) | 0.18% | — | Withsecure Elements AgentAIWithsecure Elements Client SecurityAI | 26/7/2024 | 17/6/2026 | An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security through 23.x for macOS. Local users can block an admin from completing an installation, aka a Denial-of-Service (DoS). | |
| Aplazada | Media (5.8) | 0.18% | — | Withsecure Elements AgentAIWithsecure Elements Client SecurityAIWithsecure MDRAI | 26/7/2024 | 17/6/2026 | An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x for macOS. Local Privilege Escalation can occur during installations or updates by admins. | |
| Modificada | Media (5.4) | 0.28% | — | Kraftplugins Mega Elements | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a through 1.2.2. | |
| Analizada | Media (5.3) | 0.40% | — | Wpmet Elements KIT Elementor Addons | 18/7/2024 | 17/6/2026 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts,… | |
| Modificada | Alta (8.8) | 0.57% | — | G5plus Ultimate Bootstrap Elements FOR Elementor | 9/7/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows Path Traversal.This issue affects Ultimate Bootstrap Elements for Elementor: from n/a through 1.4.2. | |
| Modificada | Media (5.3) | 0.25% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible… | |
| Modificada | Media (5.4) | 0.47% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘email’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.51% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘username’ parameter in all versions up to, and including, 1.5.112 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.50% | — | Unlimited-elements Unlimited Elements FOR Elementor (free Widgets, Addons, Templates) | 9/7/2024 | 17/6/2026 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions up to, and including, 1.5.112 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Crítica (10) | 1.1% | — | PTC Creo Elements Direct License ServerAI | 27/6/2024 | 17/6/2026 | PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server. | |
| Modificada | Media (5.4) | 0.32% | — | Webtechstreet Elementor Addon Elements | 27/6/2024 | 17/6/2026 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above,… | |
| Modificada | Media (5.4) | 0.36% | — | Webtechstreet Elementor Addon Elements | 27/6/2024 | 17/6/2026 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level permissions and above,… | |
| Analizada | Media (4.3) | 0.36% | — | Wpmet Elements KIT Elementor Addons | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0. | |
| Modificada | Media (6.3) | 0.27% | — | Crocoblock Jetelements | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. | |
| Modificada | Crítica (9.8) | 0.45% | — | Crocoblock Jetelements | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. | |
| Modificada | Alta (7.5) | 0.40% | — | Crocoblock Jetelements | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13. | |
| Modificada | Media (5.4) | 0.26% | — | Wpmet Elementskit | 15/6/2024 | 17/6/2026 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Crítica (9.6) | 0.32% | — | Wpmet Elementskit | 14/6/2024 | 17/6/2026 | The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenticated attackers, with contributor-level permissions and above, to make web requests to arbitrary locations originating from the web… | |
| Modificada | Media (5.4) | 0.32% | — | Webtechstreet Elementor Addon Elements | 12/6/2024 | 17/6/2026 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Twitter Widget in all versions up to, and including, 1.13.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 0.39% | — | Unlimited-elements Unlimited Elements FOR Elementor | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates).This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.65. |