Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.40% | — | Nextlevelbuilder GoclawAI | 5/7/2026 | 7/7/2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.13.0-beta.2. Impacted is the function MethodRouter.Handle of the file internal/gateway/router.go of the component WebSocket RPC Handler. Such manipulation leads to incorrect authorization. The attack may be launched remotely. The exploit has… | |
| Aplazada | Crítica (9.8) | 3.5% | 💥 Exploit | Divi Form BuilderAI | 2/7/2026 | 2/7/2026 | The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POST parameter is… | |
| Aplazada | Media (6.5) | 0.22% | — | Livemesh Addons FOR Wpbakery Page BuilderAI | 2/7/2026 | 2/7/2026 | Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions. | |
| Aplazada | Media (5.3) | 0.58% | — | Crocoblock JetformbuilderAI | 2/7/2026 | 2/7/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve… | |
| Aplazada | Media (6.5) | 0.55% | — | TaskbuilderAI | 1/7/2026 | 1/7/2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'task_search' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Aplazada | Media (6.5) | 0.54% | — | TaskbuilderAI | 1/7/2026 | 1/7/2026 | The Taskbuilder – Project Management & Task Management Tool With Kanban Board plugin for WordPress is vulnerable to generic SQL Injection via the 'wppm_proj_filter' parameter in all versions up to, and including, 5.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Analizada | Alta (8.2) | 0.41% | — | Electron Builder-util-runtimeElectron-builder | 30/6/2026 | 26/8/2026 | electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other credential-bearing headers — most notably… | |
| Analizada | Alta (7.8) | 0.19% | — | Electron-builder | 30/6/2026 | 18/8/2026 | electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added to the dynamic linker search path, which… | |
| Aplazada | Alta (7.1) | 0.25% | — | Pluginops Landing Page BuilderAI | 29/6/2026 | 29/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. | |
| Analizada | Crítica (10) | 31% | ⚠ Explotación activa💥 Exploit | Joomlack Page Builder CK | 29/6/2026 | 24/7/2026 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| Aplazada | Media (6.4) | 0.42% | — | Siteorigin Page BuilderAI | 27/6/2026 | 29/6/2026 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and including, 2.34.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and… | |
| Aplazada | Media (4.3) | 0.29% | — | Bopo Woocommerce Product Bundle BuilderAI | 26/6/2026 | 26/6/2026 | Unauthenticated Sensitive Data Exposure in Bopo – WooCommerce Product Bundle Builder <= 1.1.6 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Fusion BuilderAI | 26/6/2026 | 29/6/2026 | Contributor Privilege Escalation in Fusion Builder <= 3.15.4 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Funnelkit Funnel BuilderAI | 24/6/2026 | 25/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Blind SQL Injection. This issue affects Funnel Builder by FunnelKit: from n/a through 3.15.0.5. | |
| Pendiente de análisis | Media (4.1) | 0.12% | — | ABB Control Builder AAIABB 800xa FOR Advant MasterAI | 23/6/2026 | 6/10/2026 | Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1. | |
| Analizada | Crítica (10) | 89% | ⚠ Explotación activa💥 Exploit | Ollyo SP Page Builder | 20/6/2026 | 8/7/2026 | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | |
| Aplazada | Crítica (9.3) | 0.80% | — | Brainstormforce Ultimate Addons FOR Beaver BuilderAI | 20/6/2026 | 29/9/2026 | WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with the uabb-lf-google-submit action, a… | |
| Aplazada | Media (5.9) | 0.24% | — | Bricksable FOR Bricks BuilderAI | 18/6/2026 | 18/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bricks Builder allows Stored XSS. This issue affects Bricksable for Bricks Builder: from n/a through 1.6.83. | |
| Aplazada | Alta (7.7) | 0.47% | — | Avada Fusion BuilderAI | 17/6/2026 | 17/6/2026 | Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | TaskbuilderAI | 17/6/2026 | 17/6/2026 | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user. | |
| Aplazada | Media (6.8) | 0.28% | — | Crocoblock JetformbuilderAI | 17/6/2026 | 16/9/2026 | Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Fusion BuilderAI | 17/6/2026 | 17/6/2026 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. | |
| Aplazada | Media (6.5) | 0.30% | — | Wpbakery Page BuilderAI | 17/6/2026 | 17/6/2026 | Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Profile Builder PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. |