Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2627▼ 298 respecto a la semana anterior
Críticas / altas1348▲ 77 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
423 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.29% | — | Socialevolution WP Find Your NearestAI | 30/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest wp-find-your-nearest allows Stored XSS.This issue affects WP Find Your Nearest: from n/a through <= 0.3.1. | |
| Aplazada | Media (5.1) | 0.14% | — | Devolutions Xts.netAI | 27/11/2024 | 17/6/2026 | Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks | |
| Analizada | Media (4.3) | 0.55% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature. | |
| Analizada | Media (5.4) | 0.53% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching. | |
| Analizada | Media (5.4) | 0.67% | — | Devolutions Remote Desktop Manager | 25/11/2024 | 17/6/2026 | Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions. | |
| Analizada | Media (4.3) | 0.52% | — | Devolutions Server | 12/11/2024 | 17/6/2026 | Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty permission. | |
| Modificada | Media (5.4) | 0.26% | — | Brandevolutionco Themeshark Templates & Widgets FOR Elementor | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeshark ThemeShark Templates & Widgets for Elementor themeshark-elementor allows Stored XSS.This issue affects ThemeShark Templates & Widgets for Elementor: from n/a through <= 1.1.7. | |
| Modificada | Media (5.4) | 0.26% | — | Coderevolution WP Pocket Urls | 4/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution WP Pocket URLs wp-pocket-urls allows Stored XSS.This issue affects WP Pocket URLs: from n/a through <= 1.0.3. | |
| Analizada | Crítica (9.8) | 0.62% | — | Coderevolution Echo RSS Feed Post Generator | 1/10/2024 | 17/6/2026 | The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due to the plugin not properly restricting the roles that can set during registration through the echo_check_post_header_sent() function. This makes it possible for… | |
| Analizada | Media (5.4) | 0.32% | — | Themepunch Slider Revolution | 1/10/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7.18 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Modificada | Media (5.5) | 0.15% | — | Devolutions Remote Desktop Manager | 25/9/2024 | 17/6/2026 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions | |
| Modificada | Media (6.5) | 0.30% | — | Devolutions Server | 25/9/2024 | 17/6/2026 | Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, bypassing intended security restrictions, via the PAM access request approval mechanism. | |
| Analizada | Media (5.3) | 0.35% | — | Coderevolution Aiomatic | 27/7/2024 | 17/6/2026 | The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX. This makes it… | |
| Modificada | Media (4.8) | 0.26% | — | Themepunch Slider Revolution | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a through 6.7.13. | |
| Analizada | Alta (7.4) | 0.60% | — | Devolutions Remote Desktop Manager | 16/7/2024 | 17/6/2026 | Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept proxy credentials via a specially crafted website. | |
| Analizada | Alta (7.2) | 0.79% | — | Devolutions Remote Desktop Manager | 26/6/2024 | 17/6/2026 | Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission via the use of the PAM dashboard. | |
| Analizada | Media (6.3) | 0.39% | — | Devolutions Server | 25/6/2024 | 17/6/2026 | Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for the 2FA via another browser tab. | |
| Modificada | Alta (8.8) | 0.33% | — | Themepunch Slider Revolution | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ThemePunch OHG Slider Revolution.This issue affects Slider Revolution: from n/a before 6.7.0. | |
| Modificada | Media (5.4) | 0.28% | — | Themepunch Slider Revolution | 19/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemePunch OHG Slider Revolution allows Stored XSS.This issue affects Slider Revolution: from n/a before 6.7.11. | |
| Analizada | Crítica (9.8) | 0.92% | — | Devolutions Remote Desktop Manager | 17/6/2024 | 17/6/2026 | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an RDM instance to bypass the vault master password via the offline mode feature. | |
| Analizada | Media (4.7) | 0.50% | — | Devolutions Remote Desktop Manager | 17/6/2024 | 17/6/2026 | Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the configuration file. | |
| Analizada | Alta (8.8) | 0.32% | — | Coderevolution Aiomatic | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3. | |
| Modificada | Media (5.4) | 0.26% | — | Themepunch Slider Revolution | 4/6/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 6.7.10 due to insufficient input sanitization and output escaping on the user supplied Elementor 'wrapperid' and 'zindex' display attributes. This makes it possible for authenticated attackers,… | |
| Modificada | Media (5.4) | 0.28% | — | Themepunch Slider Revolution | 4/6/2024 | 17/6/2026 | The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Add Layer widget in all versions up to, and including, 6.7.11 due to insufficient input sanitization and output escaping on the user supplied 'class', 'id', and 'title' attributes. This makes it possible for… | |
| Analizada | Media (6.5) | 0.68% | — | Devolutions Server | 17/5/2024 | 17/6/2026 | Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the PAM JIT elevation feature to manipulate the LDAP filter query via a specially crafted request. |