Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2576▼ 298 respecto a la semana anterior
Críticas / altas1356▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.67% | — | Welcome Software PublishingAI | 24/6/2026 | 25/6/2026 | The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function authenticates the user via… | |
| Aplazada | Media (5.3) | 0.20% | — | Ideabox Creations Dashboard Welcome FOR Beaver BuilderAIFastlinemedia Beaver BuilderAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in IdeaBox Creations Dashboard Welcome for Beaver Builder dashboard-welcome-for-beaver-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dashboard Welcome for Beaver Builder: from n/a through <= 1.0.8. | |
| Aplazada | Crítica (9.4) | 0.59% | — | Bewelcome ROXAI | 27/10/2025 | 14/7/2026 | Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of untrusted data. User-controlled input is passed to PHP's unserialize(): the POST parameter `formkit_memory_recovery` in \\RoxPostHandler::getCallbackAction and the 'memory cookie' read by… | |
| Aplazada | Alta (7.1) | 0.15% | — | Eslam Mahmoud Redirect Wordpress TO Welcome OR Landing PageAI | 17/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Eslam Mahmoud Redirect wordpress to welcome or landing page redirect-to-welcome-or-landing-page allows Stored XSS.This issue affects Redirect wordpress to welcome or landing page: from n/a through <= 2.0. | |
| Aplazada | Media (5.9) | 0.40% | — | Data443 Risk Mitigation INC Welcome BARAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Risk Mitigation, Inc. Welcome Bar intelly-welcome-bar allows Stored XSS.This issue affects Welcome Bar: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.9) | 0.21% | — | Weblineindia Welcome PopupAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WeblineIndia Welcome Popup welcome-popup allows Stored XSS.This issue affects Welcome Popup: from n/a through <= 1.0.10. | |
| Aplazada | Alta (7.1) | 0.28% | — | Pantho Bihosh PIT Login WelcomeAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pantho Bihosh Pit Login Welcome pit-login-welcome allows Reflected XSS.This issue affects Pit Login Welcome: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.33% | — | Davidvongries Welcome Email EditorAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in David Vongries Welcome Email Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Welcome Email Editor: from n/a through 5.0.6. | |
| Modificada | Alta (7.8) | 0.31% | — | Opensuse Welcome | 19/9/2023 | 17/6/2026 | A Insecure Storage of Sensitive Information vulnerability in openSUSE opensuse-welcome allows local attackers to execute code as the user that runs opensuse-welcome if a custom layout is chosen This issue affects opensuse-welcome: from 0.1 before 0.1.9+git.35.4b9444a. | |
| Modificada | Media (6.1) | 0.63% | — | Resend Welcome Email Project Resend Welcome Email | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading… | |
| Modificada | Media (5.4) | 0.60% | — | Icegram Popups, Welcome Bar, Optins AND Lead Generation Plugin | 27/6/2022 | 17/6/2026 | The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.1.8 does not sanitize and escape some campaign parameters, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.88% | — | Tubigan Welcome TO OUR Resort | 18/6/2019 | 17/6/2026 | The Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit. | |
| Modificada | Crítica (9.8) | 3.2% | — | Tubigan Welcome TO OUR Resort | 14/5/2019 | 17/6/2026 | The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php. |