Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/10/2026 | 6/10/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Parameter Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Alta (8.4) | 0.35% | — | Mitel Mivoice Office 400AI | 5/10/2026 | 6/10/2026 | This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is… | |
| Aplazada | Alta (8.4) | 0.09% | — | Mitel Linux Virtual MachineAI | 5/10/2026 | 6/10/2026 | DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Alta (7.1) | 0.15% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 4/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Alta (7.1) | 0.15% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected XSS.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons,… | |
| Aplazada | Media (6.3) | 0.18% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise and escape a parameter before using it in a SQL statement, allowing users with a role as low as subscriber to perform blind SQL injection attacks and read arbitrary data from the database. Version 2.0.18 removed the subscriber-level… | |
| Aplazada | Media (6.8) | 0.22% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not correctly handle a search value before rewriting an already prepared SQL statement, allowing unauthenticated users to perform SQL injection attacks and to retrieve non-public content, when a related widget option is set away from its default. | |
| Aplazada | Media (6.6) | 0.42% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/10/2026 | 6/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not sanitise file paths inside uploaded archives before extracting them, allowing authenticated users with access to its asset-management feature (Administrators by default, or Editors when a non-default Unlimited Elements for Elementor WordPress… | |
| Aplazada | Media (5.4) | 0.18% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 2/10/2026 | 2/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not check that a request to render widget output comes from a user allowed to make it, allowing users with a role as low as subscriber to have arbitrary WordPress shortcodes executed on the site. Version 2.0.18 removed the subscriber-level… | |
| Aplazada | Media (6.8) | 0.24% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 2/10/2026 | 2/10/2026 | The Unlimited Elements for Elementor WordPress plugin before 2.0.21 does not escape an icon value before concatenating it into an HTML attribute in its shared widget-parameter processor, allowing users with Contributor access (who do not hold unfiltered_html) to store a payload that executes when the page is rendered. | |
| Aplazada | Media (5.3) | 0.19% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates):… | |
| Aplazada | Alta (8.5) | 0.21% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 1/10/2026 | 1/10/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets,… | |
| Aplazada | Alta (8.7) | 0.66% | — | MarmiteAI | 29/9/2026 | 30/9/2026 | Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in… | |
| Aplazada | Alta (8.7) | 0.39% | — | MarmiteAI | 29/9/2026 | 30/9/2026 | Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder,… | |
| Aplazada | Alta (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 29/9/2026 | 30/9/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Aplazada | Alta (7.5) | 0.40% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 20/9/2026 | 21/9/2026 | The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the… | |
| Aplazada | Media (6.4) | 0.23% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 17/9/2026 | 17/9/2026 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.19 versions. | |
| Aplazada | Media (6.1) | 0.45% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 11/9/2026 | 11/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.5) | 0.33% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 11/9/2026 | 11/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the existing SQL query in the getWhereString()… | |
| Aplazada | Alta (7.1) | 0.25% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions. | |
| Aplazada | Media (6.1) | 0.38% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 5/9/2026 | 8/9/2026 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including, 2.0.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (5.3) | 0.31% | — | Unlimited-elements Unlimited Elements FOR ElementorAI | 3/9/2026 | 3/9/2026 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.17. | |
| Aplazada | Media (6.4) | 0.26% | — | ALL IN ONE WP Migration Unlimited ExtensionAI | 28/8/2026 | 28/8/2026 | The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and including, 2.84. This is due to insufficient input sanitization and output escaping on user-supplied attributes combined with missing… | |
| Aplazada | Media (4.3) | 0.28% | — | Softtr Informatics Technology Trading Limited E-commerce PackAI | 27/8/2026 | 28/8/2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting (XSS). This issue affects E-Commerce Pack: before 5.03.01.49. |