Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.50% | — | Designthemes LMS Elementor PROAI | 5/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in designthemes LMS Elementor Pro lms-elementor-pro allows Privilege Escalation.This issue affects LMS Elementor Pro: from n/a through <= 1.0.4. | |
| Aplazada | Alta (8.8) | 0.58% | — | Designthemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.8) | 0.67% | — | Designthemes Wedesigntech Ultimate Booking AddonAI | 5/3/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in designthemes WeDesignTech Ultimate Booking Addon wedesigntech-ultimate-booking-addon allows Authentication Abuse.This issue affects WeDesignTech Ultimate Booking Addon: from n/a through <= 1.0.1. | |
| Aplazada | Alta (7.5) | 0.36% | — | Designthemes Directory AddonAI | 5/3/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes DesignThemes Directory Addon designthemes-directory-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes Directory Addon: from n/a through <= 1.8. | |
| Aplazada | Alta (7.1) | 0.26% | — | Designthemes PortfolioAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio designthemes-portfolio allows Reflected XSS.This issue affects DesignThemes Portfolio: from n/a through <= 1.3. | |
| Aplazada | Alta (8.8) | 0.38% | — | Designthemes Dental ClinicAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Dental Clinic dental allows Object Injection.This issue affects Dental Clinic: from n/a through <= 3.7. | |
| Aplazada | Alta (7.1) | 0.19% | — | Designthemes Core FeaturesAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core Features designthemes-core-features allows Reflected XSS.This issue affects DesignThemes Core Features: from n/a through <= 2.3. | |
| Aplazada | Media (6.5) | 0.28% | — | Designthemes Dt-reservation-pluginAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reservation Plugin: from n/a through <= 1.7. | |
| Aplazada | Alta (8.8) | 0.41% | — | Designthemes OnelifeAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes OneLife onelife allows Object Injection.This issue affects OneLife: from n/a through <= 3.9. | |
| Aplazada | Alta (8.8) | 0.47% | — | Designthemes VivaghAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Vivagh vivagh allows Object Injection.This issue affects Vivagh: from n/a through <= 2.4. | |
| Aplazada | Alta (8.8) | 0.64% | — | Designthemes Kids HeavenAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n/a through <= 3.2. | |
| Aplazada | Media (5.3) | 0.25% | — | Designthemes LMS AddonAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in designthemes DesignThemes LMS Addon designthemes-lms-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DesignThemes LMS Addon: from n/a through <= 2.6. | |
| Aplazada | Media (5.3) | 0.25% | — | Designthemes Homefix Elementor PortfolioAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in designthemes HomeFix Elementor Portfolio homefix-ele-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HomeFix Elementor Portfolio: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Designthemes Wedesigntech PortfolioAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in designthemes WeDesignTech Portfolio wedesigntech-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WeDesignTech Portfolio: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.20% | — | Designthemes CoreAI | 30/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Core designthemes-core allows DOM-Based XSS.This issue affects DesignThemes Core: from n/a through <= 1.6. | |
| Aplazada | Media (6.5) | 0.19% | — | Designthemes Portfolio AddonAI | 30/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio Addon designthemes-portfolio-addon allows DOM-Based XSS.This issue affects DesignThemes Portfolio Addon: from n/a through <= 1.5. | |
| Aplazada | Alta (7.1) | 0.22% | — | Designthemes Dt-reservation-pluginAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Reservation Plugin dt-reservation-plugin allows Reflected XSS.This issue affects Reservation Plugin: from n/a through <= 1.6. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Designthemes LMSAI | 2/12/2025 | 17/6/2026 | The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the… | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Single PropertyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Knowledge BaseAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Knowledge Base kbase allows Object Injection.This issue affects Knowledge Base: from n/a through <= 2.9. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes KriyaAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Kriya kriya allows Object Injection.This issue affects Kriya: from n/a through <= 3.4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Designthemes TrissAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Triss triss allows Reflected XSS.This issue affects Triss: from n/a through <= 2.6. | |
| Aplazada | Alta (8.8) | 0.61% | — | Designthemes Solar EnergyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Solar Energy solar allows Object Injection.This issue affects Solar Energy: from n/a through <= 3.5. | |
| Aplazada | Alta (7.1) | 0.24% | — | Designthemes InvicoAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes Invico - WordPress Consulting Business Theme invico allows Reflected XSS.This issue affects Invico - WordPress Consulting Business Theme: from n/a through <= 1.9. | |
| Aplazada | Alta (8.8) | 0.46% | — | Designthemes Visual ART GalleryAI | 16/7/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Visual Art | Gallery WordPress Theme visual-arts allows Object Injection.This issue affects Visual Art | Gallery WordPress Theme: from n/a through <= 2.4. |