Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.94% | 💥 Exploit | Lottiefiles Lottie Block FOR GutenbergAI | 14/1/2026 | 17/6/2026 | The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.0 via the `/wp-json/lottiefiles/v1/settings/` REST API endpoint. This makes it possible for unauthenticated attackers to retrieve the site owner's LottieFiles.com… | |
| Aplazada | Media (4.4) | 0.22% | — | Gotham Block Extra LightAI | 14/1/2026 | 17/6/2026 | The Gotham Block Extra Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Aplazada | Media (6.5) | 0.36% | — | Gotham Block Extra LightAI | 14/1/2026 | 17/6/2026 | The Gotham Block Extra Light plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.5.0 via the 'ghostban' shortcode. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can… | |
| Analizada | Media (5.3) | 0.13% | — | Tox-dev Filelock | 10/1/2026 | 17/6/2026 | filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission… | |
| Aplazada | Media (6.5) | 0.31% | — | Munir Kamal Block SliderAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Munir Kamal Block Slider block-slider allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Block Slider: from n/a through <= 2.2.3. | |
| Aplazada | Alta (7.5) | 0.34% | — | Kaira BlockonsAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Kaira Blockons blockons allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blockons: from n/a through <= 1.2.19. | |
| Aplazada | Media (5.3) | 0.23% | — | AA Block CountryAI | 7/1/2026 | 17/6/2026 | The AA Block Country plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.0.1. This is due to the plugin trusting user-supplied headers such as HTTP_X_FORWARDED_FOR to determine the client's IP address without proper validation or considering if the server is behind a trusted… | |
| Aplazada | Media (5.4) | 0.25% | — | Tusharimran AblocksAI | 7/1/2026 | 15/9/2026 | The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.19% | — | Crocoblock JetengineAI | 7/1/2026 | 7/10/2026 | Missing Authorization vulnerability in Crocoblock JetEngine jet-engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetEngine: from n/a through <= 3.8.1.1. | |
| Aplazada | Media (5.3) | 0.33% | 💥 PoC | Auntyfey Smart Combination LockAI | 7/1/2026 | 7/10/2026 | AuntyFey Smart Combination Lock firmware versions as of 2025-12-24 contain a vulnerability that allows an unauthenticated attacker within Bluetooth Low Energy (BLE) range to cause a denial of service by repeatedly initiating BLE connections. Sustained connection attempts interrupt keypad authentication input and… | |
| Aplazada | Media (4.3) | 0.18% | — | Proxy & VPN BlockerAI | 6/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.3. | |
| Aplazada | Media (4.3) | 0.18% | — | Affiliatexblocks AffiliatexAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in WPCenter AffiliateX affiliatex allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AffiliateX: from n/a through <= 1.3.9.3. | |
| Aplazada | Alta (8.7) | 0.37% | — | OpenblocksAI | 6/1/2026 | 17/6/2026 | Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password. | |
| Aplazada | Media (6.5) | 0.19% | — | Landwire Responsive Block ControlAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in landwire Responsive Block Control responsive-block-control allows DOM-Based XSS.This issue affects Responsive Block Control: from n/a through <= 1.3.0. | |
| Aplazada | Media (6.5) | 0.17% | — | Justintadlock SeriesAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Series series allows Stored XSS.This issue affects Series: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Maksym Marko MX Time Zone ClocksAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maksym Marko MX Time Zone Clocks mx-time-zone-clocks allows Stored XSS.This issue affects MX Time Zone Clocks: from n/a through <= 5.1.1. | |
| Aplazada | Media (4.3) | 0.33% | — | Sitelock SecurityAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in SiteLock SiteLock Security – WP Hardening, Login Security & Malware Scans sitelock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SiteLock Security – WP Hardening, Login Security & Malware Scans: from n/a through <= 5.0.1. | |
| Aplazada | Media (6.5) | 0.16% | — | Crocoblock JettabsAI | 29/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.12. | |
| Aplazada | Media (6.5) | 0.24% | — | Crocoblock JettabsAI | 29/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Crocoblock JetTabs jet-tabs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetTabs: from n/a through <= 2.2.12. | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JetsearchAI | 29/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16. | |
| Aplazada | Media (6.5) | 0.31% | — | Crocoblock JetblogAI | 29/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7. | |
| Aplazada | Media (4.3) | 0.27% | — | Crocoblock JetpopupAI | 29/12/2025 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Crocoblock JetPopup jet-popup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetPopup: from n/a through <= 2.0.20.1. | |
| Aplazada | Alta (7.5) | 0.39% | — | Subscribe TO Unlock LiteAI | 24/12/2025 | 7/10/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WP Shuffle Subscribe to Unlock Lite subscribe-to-unlock-lite allows PHP Local File Inclusion.This issue affects Subscribe to Unlock Lite: from n/a through <= 1.3.0. | |
| Aplazada | Media (6.5) | 0.16% | — | Crocoblock Jetelements FOR ElementorAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12. | |
| Aplazada | Media (5.3) | 0.24% | — | Pickplugins Post Grid AND Gutenberg BlocksAI | 18/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. |