Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 410 respecto a la semana anterior
Críticas / altas1307▲ 25 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.0% | — | WebinfosAI | 3/8/2026 | 26/8/2026 | The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authentication, capability, or nonce check, allowing unauthenticated attackers to upload arbitrary files (including PHP) to a web-accessible directory, leading to remote code… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Webilia INC ListdomAI | 17/6/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0. | |
| Aplazada | Crítica (9.8) | 0.53% | — | Saleswonder Team Webinar IgnitionAI | 27/5/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253. | |
| Aplazada | Crítica (9.9) | 0.55% | — | Saleswonder Team Webinar IgnitionAI | 27/5/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Saleswonder WebinarignitionAI | 5/5/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder LLC WebinarIgnition allows Blind SQL Injection. This issue affects WebinarIgnition: from n/a through 4.08.253. | |
| Aplazada | Media (6.5) | 0.29% | — | Webilia INC Vertex Addons FOR ElementorAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vertex Addons for Elementor: from n/a through <= 1.6.4. | |
| Analizada | Media (4.3) | 0.14% | — | Webikon Theme Negotiation BY Rules | 25/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross Site Request Forgery.This issue affects Theme Negotiation by Rules: from 0.0.0 before 1.2.1. | |
| Aplazada | Alta (8.8) | 0.24% | — | Webincorp ERPAI | 22/2/2026 | 17/6/2026 | WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter. Attackers can send GET requests to product_detail.php with malicious prod_id values to extract sensitive database information. | |
| Aplazada | Alta (7.1) | 0.99% | — | WebileAI | 1/2/2026 | 17/6/2026 | Webile 1.0.1 contains a directory traversal vulnerability that allows remote attackers to manipulate file system paths without authentication. Attackers can exploit path manipulation to access sensitive system directories and potentially compromise the mobile device's local file system. | |
| Aplazada | Media (6.5) | 0.32% | — | Saleswonder Team Webinar-ignitionAI | 18/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarIgnition: from n/a through <= 4.06.04. | |
| Aplazada | Alta (8.7) | 0.51% | — | WebigniterAI | 15/12/2025 | 17/6/2026 | WEBIGniter 28.7.23 contains a file upload vulnerability that allows authenticated attackers to upload and execute dangerous PHP files through the media function. Attackers can leverage any created account to upload malicious PHP scripts that enable remote code execution on the application server. | |
| Aplazada | Media (5.4) | 0.27% | — | Webilia INC ListdomAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Webilia Inc. Listdom listdom allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Listdom: from n/a through <= 5.0.1. | |
| Aplazada | Media (5.3) | 0.41% | — | WebigniterAI | 4/12/2025 | 17/6/2026 | WEBIGniter 28.7.23 contains a cross-site scripting vulnerability in the user creation process that allows unauthenticated attackers to execute malicious JavaScript code, enabling potential XSS attacks. | |
| Analizada | Alta (7.1) | 0.45% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.32% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Alta (7.1) | 0.32% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Alta (7.7) | 0.40% | — | Uniong Webitr | 28/11/2025 | 17/6/2026 | WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. Attackers must first obtain a user ID to exploit this vulnerability. | |
| Modificada | Media (4.3) | 0.27% | — | Webinarpress | 27/10/2025 | 5/10/2026 | Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebinarPress: from n/a through <= 1.33.28. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (7.1) | 0.55% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files. | |
| Analizada | Alta (8.7) | 0.52% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Analizada | Crítica (9.3) | 0.65% | — | Uniong Webitr | 22/8/2025 | 17/6/2026 | WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality. | |
| Aplazada | Alta (7.1) | 0.23% | — | Webilop User Language SwitchAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webilop User Language Switch user-language-switch allows Reflected XSS.This issue affects User Language Switch: from n/a through <= 1.6.10. |