Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.21% | — | Radiustheme Radius BlocksAI | 18/12/2025 | 30/9/2026 | Authorization Bypass Through User-Controlled Key vulnerability in RadiusTheme Radius Blocks radius-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Radius Blocks: from n/a through <= 2.2.1. | |
| Modificada | Media (6.1) | 0.12% | — | Drivelock | 17/12/2025 | 17/6/2026 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 before 24.2.8, and 25.1 before 25.1.6. Directories and files created by the agent are created with overly permissive ACLs, allowing local users without administrator rights to trigger actions or destabilize the agent. | |
| Analizada | Crítica (9.8) | 0.32% | — | Drivelock | 17/12/2025 | 17/6/2026 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "Manage roles and permissions" privilege can promote themselves or other DOC users to the Supervisor role through an API call. This privilege is included by default in the Administrator role. This… | |
| Modificada | Alta (7.8) | 0.14% | — | Drivelock | 17/12/2025 | 17/6/2026 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate a DriveLock process to execute arbitrary commands on Windows computers. | |
| Modificada | Alta (7.5) | 0.32% | — | Drivelock | 17/12/2025 | 17/6/2026 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unprivileged user could cause occasionally a Blue Screen Of Death (BSOD) on Windows computers by using an IOCTL and an unterminated string. | |
| Analizada | Media (5.3) | 0.22% | — | Drivelock | 17/12/2025 | 17/6/2026 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Authenticated users can retrieve the computer count of other DriveLock tenants via the DriveLock API. | |
| Modificada | Crítica (9.8) | 0.37% | — | Drivelock | 17/12/2025 | 25/9/2026 | An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the network against the DES (DriveLock Enterprise Service). | |
| Analizada | Crítica (9.9) | 0.28% | — | Drivelock | 17/12/2025 | 17/6/2026 | An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers. | |
| Analizada | Crítica (9.6) | 0.26% | — | Drivelock | 17/12/2025 | 25/9/2026 | An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network. | |
| Aplazada | Media (4.3) | 0.32% | — | Wpdeveloper Essential BlocksAI | 17/12/2025 | 17/6/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unauthorized access of data due to a missing or incorrect capability checks on the get_instagram_access_token_callback, google_map_api_key_save_callback and get_siteinfo functions in all versions up to,… | |
| Analizada | Media (6.5) | 0.20% | — | Tox-dev Filelock | 16/12/2025 | 17/6/2026 | filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock… | |
| Aplazada | Media (5.3) | 0.22% | — | Crocoblock JetformbuilderAI | 16/12/2025 | 7/10/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the run_callback function in all versions up to, and including, 3.5.3. This makes it possible for unauthenticated attackers to generate forms using AI, consuming… | |
| Aplazada | Media (6.4) | 0.22% | — | Crocoblock Jetwidgets FOR ElementorAI | 13/12/2025 | 7/10/2026 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison and Subscribe widgets in all versions up to, and including, 1.0.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Gallery Blocks With LightboxAI | 13/12/2025 | 7/10/2026 | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to unauthorized modification of plugin settings in all versions up to, and including, 3.3.0. This is due to the plugin using the `edit_posts` capability check… | |
| Aplazada | Media (4.3) | 0.35% | — | GenerateblocksAI | 13/12/2025 | 7/10/2026 | The GenerateBlocks plugin for WordPress is vulnerable to information exposure due to missing object-level authorization checks in versions up to, and including, 2.1.2. This is due to the plugin registering multiple REST API routes under `generateblocks/v1/meta/` that gate access with `current_user_can('edit_posts')`,… | |
| Aplazada | Media (5.3) | 0.45% | — | Login Lockdown ProtectionAI | 13/12/2025 | 7/10/2026 | The Login Lockdown & Protection plugin for WordPress is vulnerable to IP Block Bypass in all versions up to, and including, 2.14. This is due to $unblock_key key being insufficiently random allowing unauthenticated users, with access to an administrative user email, to generate valid unblock keys for their IP Address.… | |
| Aplazada | Media (5.3) | 0.32% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 12/12/2025 | 7/10/2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to sensitive information exposure due to storage of exported CSV files in a publicly accessible directory with predictable filenames in all versions up to, and including, 4.9.2. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.16% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 12/12/2025 | 7/10/2026 | The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.9.2. This is due to missing nonce validation on the 'ays_sccp_results_export_file' AJAX action. This makes it possible for unauthenticated attackers to export… | |
| Aplazada | Media (4.3) | 0.16% | — | Coding BlocksAI | 12/12/2025 | 7/10/2026 | The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update plugin settings including the theme configuration… | |
| Aplazada | Media (6.4) | 0.22% | — | APP Landing Template BlocksAI | 12/12/2025 | 7/10/2026 | The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'atvc_video_play' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Aplazada | Media (5.3) | 0.21% | — | Wbcomdesigns Lock-my-bpAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wbcomdesigns Wbcom Designs lock-my-bp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wbcom Designs: from n/a through <= 2.1.1. | |
| Aplazada | Baja (2.7) | 0.24% | — | Ronald Huereca Photo BlockAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through <= 1.5.1. | |
| Aplazada | Media (6.4) | 0.18% | — | BlockartAI | 2/12/2025 | 17/6/2026 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘timestamp’ attribute in all versions up to, and including, 2.2.13 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Baja (0.3) | 0.14% | — | Motogadget Mo.lockAI | 29/11/2025 | 7/10/2026 | A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing a manipulation can lead to use of hard-coded cryptographic key . The physical device can be targeted for the attack. A high complexity… | |
| Aplazada | Media (5.3) | 0.29% | — | Locker ContentAI | 25/11/2025 | 17/6/2026 | The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'lockerco_submit_post' AJAX endpoint. This makes it possible for unauthenticated attackers to extract content from posts that has been protected by the plugin. |