Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
496 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.58% | — | Angeljudesuarez E-commerce Website | 25/8/2024 | 17/6/2026 | A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file search_list.php. The manipulation of the argument user leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.9) | 0.49% | — | Oretnom23 Simple Forum Website | 19/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. The manipulation of the argument username leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Aplazada | Alta (7.1) | 0.16% | — | Northernbeacheswebsites WP GotowebinarAI | 2/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7. | |
| Modificada | Media (5.4) | 0.26% | — | Northernbeacheswebsites Ideapush | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60. | |
| Modificada | Media (6.1) | 0.33% | — | Northernbeacheswebsites Ideapush | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.65. | |
| Aplazada | Media (6.5) | 0.34% | — | Northernbeacheswebsites WP GotowebinarAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson WP GoToWebinar allows Stored XSS.This issue affects WP GoToWebinar: from n/a through 15.7. | |
| Modificada | Media (5.4) | 0.31% | — | Matteoenna Website Content IN Page OR Post | 12/7/2024 | 17/6/2026 | The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.34% | — | Elementor Website Builder | 9/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elementor Website Builder elementor.This issue affects Elementor Website Builder: from n/a through <= 3.22.1. | |
| Aplazada | Media (5.3) | 0.51% | — | Webtoffee Preloader FOR WebsiteAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in WP OnlineSupport, Essential Plugin Preloader for Website.This issue affects Preloader for Website: from n/a through 1.2.2. | |
| Modificada | Media (4.3) | 0.34% | — | Elementor Website Builder | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2. | |
| Aplazada | Media (4.3) | 0.41% | — | Northernbeacheswebsites WP GotowebinarAI | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Martin Gibson WP GoToWebinar.This issue affects WP GoToWebinar: from n/a through 14.46. | |
| Modificada | Media (5.4) | 0.28% | — | Visualcomposer Visual Composer Website Builder | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: from n/a through <= 45.8.0. | |
| Modificada | Media (5.4) | 0.40% | — | Elementor Website Builder | 21/5/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the ‘hover_animation’ parameter in versions up to, and including, 3.21.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Alta (8.1) | 0.71% | — | Elementor Website Builder | 17/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0. | |
| Analizada | Media (5.3) | 0.43% | — | Oretnom23 Simple Image Stack Website | 16/5/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This affects an unknown part. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Media (5.4) | 0.42% | — | Elementor Website Builder | 14/5/2024 | 17/6/2026 | The Elementor Website Builder – More than Just a Page Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the several parameters in versions up to, and including, 3.21.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Elementor Website Builder | 24/4/2024 | 17/6/2026 | Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4. | |
| Analizada | Alta (8.8) | 0.71% | — | Oretnom23 Simple Subscription Website | 24/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Simple Subscription Website 1.0. Affected is an unknown function of the file view_application.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (6.1) | 0.57% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file login.php. The manipulation of the argument txtAddress leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.57% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file prodInfo.php. The manipulation of the argument prodId leads to cross site scripting. The attack may be launched remotely. The… | |
| Modificada | Media (5.4) | 0.52% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file prodList.php. The manipulation of the argument prodType leads to cross site scripting. The attack can be launched remotely.… | |
| Modificada | Media (5.4) | 0.52% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as problematic. Affected is an unknown function of the file search.php. The manipulation of the argument txtSearch leads to cross site scripting. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.66% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This issue affects some unknown processing of the file prodInfo.php. The manipulation of the argument prodId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to… | |
| Analizada | Alta (7.5) | 0.60% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file prodList.php. The manipulation of the argument prodType leads to sql injection. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.5) | 0.60% | — | Aditya88 Online Furniture Shopping Ecommerce Website | 23/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. This affects an unknown part of the file search.php. The manipulation of the argument txtSearch leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |