Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
506 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.34% | — | Wpdeveloper Simple 301 RedirectsAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Simple 301 Redirects by BetterLinks simple-301-redirects allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple 301 Redirects by BetterLinks: from n/a through <= 2.0.7. | |
| Modificada | Alta (8.8) | 0.40% | — | Wpdeveloper Essential Blocks | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.2.0. | |
| Aplazada | Media (5.3) | 0.45% | — | Wpexpertdeveloper WP Private Content PlusAI | 6/12/2024 | 17/6/2026 | The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles… | |
| Analizada | Media (5.4) | 0.37% | — | Wpdeveloper Embedpress | 28/11/2024 | 17/6/2026 | The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘provider_name parameter in all versions up to, and including, 4.1.3 due to insufficient input… | |
| Aplazada | Media (6.5) | 0.32% | — | Best WP Developer Gutenium BlocksAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Best WP Developer Gutenium Blocks gutenium allows Stored XSS.This issue affects Gutenium Blocks: from n/a through <= 1.1.7. | |
| Analizada | Media (5.7) | 0.50% | — | Wpdeveloper Essential Addons FOR Elementor | 15/11/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for… | |
| Analizada | Media (5.7) | 0.47% | — | Wpdeveloper Essential Addons FOR Elementor | 15/11/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for… | |
| Analizada | Media (5.4) | 0.30% | — | Wpdeveloper Essential Addons FOR Elementor | 15/11/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘nomore_items_text’ parameter in all versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This… | |
| Modificada | Alta (7.2) | 0.46% | — | Wpdeveloper Betterlinks | 4/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a through <= 2.1.7. | |
| Modificada | Crítica (9.8) | 0.48% | — | Wpdeveloper Reviewx | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in ReviewX ReviewX allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ReviewX: from n/a through 1.6.28. | |
| Analizada | Alta (8.8) | 0.42% | — | Wpdeveloper Embedpress | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper EmbedPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EmbedPress: from n/a through 4.0.4. | |
| Aplazada | Media (6.5) | 0.38% | — | Wpdeveloper TemplatelyAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through <= 3.1.5. | |
| Aplazada | Media (5.4) | 0.39% | — | Wpdeveloper TemplatelyAI | 29/10/2024 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Templately: from n/a through <= 3.1.5. | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Embedpress | 28/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper EmbedPress embedpress allows Stored XSS.This issue affects EmbedPress: from n/a through <= 4.0.14. | |
| Modificada | Media (5.4) | 0.27% | — | Swebdeveloper Wppricing Builder | 18/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swebdeveloper wpPricing Builder wppricing-builder-lite-responsive-pricing-table-builder allows Stored XSS.This issue affects wpPricing Builder: from n/a through <= 1.5.0. | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 16/10/2024 | 17/6/2026 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data. | |
| Analizada | Alta (8.8) | 0.46% | — | Wpdeveloper Essential Addons FOR Elementor | 16/10/2024 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the… | |
| Analizada | Media (4.3) | 0.26% | — | Wpdeveloper Essential Addons FOR Elementor | 16/10/2024 | 17/6/2026 | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized… | |
| Analizada | Alta (8.8) | 0.18% | — | Rockwellautomation Rslogix 5Rockwellautomation Rslogix 500Rockwellautomation Rslogix Micro DeveloperRockwellautomation Rslogix Micro Starter Lite | 14/10/2024 | 17/6/2026 | VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A feature in the affected products enables users to prepare a project file with an… | |
| Modificada | Media (5.4) | 0.26% | — | Wpdeveloper Essential Blocks | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper Essential Blocks for Gutenberg essential-blocks allows Stored XSS.This issue affects Essential Blocks for Gutenberg: from n/a through <= 4.8.4. | |
| Aplazada | Media (6.5) | 0.26% | — | Wpdeveloperr Confetti Fall AnimationAI | 30/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel Confetti Fall Animation confetti-fall-animation allows Stored XSS.This issue affects Confetti Fall Animation: from n/a through <= 1.3.0. | |
| Modificada | Media (5.4) | 0.34% | — | Wpdeveloperr Confetti Fall Animation | 25/9/2024 | 17/6/2026 | The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti-fall-animation' shortcode in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.37% | — | Wpdeveloper Essential Addons FOR Elementor | 13/9/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping… | |
| Analizada | Media (5.4) | 0.39% | — | Wpdeveloper Essential Addons FOR Elementor | 11/9/2024 | 17/6/2026 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy Text widget in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user… | |
| Analizada | Media (4.8) | 0.35% | — | Just-a-web-developer Floating Contact Button | 10/9/2024 | 17/6/2026 | The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed |