Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.67% | — | Flocksafety Flock Safety | 2/10/2025 | 17/6/2026 | The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a… | |
| Analizada | Media (6.2) | 0.17% | — | Flocksafety Flock Safety | 2/10/2025 | 17/6/2026 | The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, attackers can… | |
| Analizada | Alta (7.5) | 0.47% | — | Flocksafety Flock Safety | 2/10/2025 | 17/6/2026 | The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because application binaries can be trivially decompiled or inspected,… | |
| Modificada | Crítica (9.8) | 1.1% | — | Flocksafety Flock Safety | 2/10/2025 | 17/6/2026 | The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include but are not limited… | |
| Aplazada | Media (6.4) | 0.25% | — | Zelabs ZoloblocksAI | 1/10/2025 | 17/6/2026 | The ZoloBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Gutenberg blocks in versions up to, and including, 2.3.10. This is due to insufficient input sanitization and output escaping on user-supplied attributes within multiple block components including Google Maps markers,… | |
| Aplazada | Media (4) | 0.30% | — | Block FOR MailchimpAI | 1/10/2025 | 1/10/2026 | The Block For Mailchimp – Easy Mailchimp Form Integration plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.12 via the mcbSubmit_Form_Data(). This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from… | |
| Aplazada | Media (6.1) | 0.16% | — | LockerpressAI | 30/9/2025 | 17/6/2026 | The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Aplazada | Media (6.4) | 0.24% | — | Nexa BlocksAI | 30/9/2025 | 17/6/2026 | The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Crítica (9.9) | 0.45% | — | Drivelock | 26/9/2025 | 17/6/2026 | In DriveLock 24.1.4 before 24.1.5, 24.2.5 before 24.2.6, and 25.1.2 before 25.1.4, attackers can gain elevated privileges. | |
| Aplazada | Alta (7.1) | 0.12% | — | Taraprasad Swain Htaccess IP BlockerAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Stored XSS.This issue affects HTACCESS IP Blocker: from n/a through <= 1.0. | |
| Aplazada | Media (5.4) | 0.21% | — | Bdthemes ZoloblocksAI | 26/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in bdthemes ZoloBlocks zoloblocks allows Server Side Request Forgery.This issue affects ZoloBlocks: from n/a through <= 2.3.11. | |
| Aplazada | Alta (7.5) | 0.48% | — | Wpshuffle Subscribe TO UnlockAI | 26/9/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows PHP Local File Inclusion.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5. | |
| Aplazada | Media (4.3) | 0.24% | — | Wpshuffle Subscribe TO UnlockAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in wpshuffle Subscribe To Unlock subscribe-to-unlock allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Subscribe To Unlock: from n/a through <= 1.1.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Sktthemes SKT BlocksAI | 26/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows Stored XSS.This issue affects SKT Blocks: from n/a through <= 2.6. | |
| Aplazada | Media (4.3) | 0.27% | — | Stackable-ultimate-gutenberg-blocksAI | 26/9/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Retrieve Embedded Sensitive Data.This issue affects Stackable: from n/a through <= 3.18.1. | |
| Aplazada | Media (4.3) | 0.24% | — | Stackable-ultimate-gutenberg-blocksAI | 26/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stackable: from n/a through <= 3.18.1. | |
| Analizada | Alta (7.3) | 0.25% | — | Flocksafety Bravo Compute BOX Firmware | 25/9/2025 | 17/6/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections. | |
| Analizada | Alta (7.5) | 0.43% | — | Flocksafety Bravo Compute BOX Firmware | 25/9/2025 | 17/6/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions. | |
| Analizada | Media (5.4) | 0.23% | — | Flocksafety Bravo Compute BOX Firmware | 25/9/2025 | 17/6/2026 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls. | |
| Aplazada | Media (4.3) | 0.25% | — | Hashthemes Smart BlocksAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in hashthemes Smart Blocks smart-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Blocks: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.25% | — | Thedevoice Lazy BlocksAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in nK Lazy Blocks lazy-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lazy Blocks: from n/a through <= 4.1.0. | |
| Aplazada | Media (6.5) | 0.21% | — | Bdthemes ZoloblocksAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bdthemes ZoloBlocks zoloblocks allows DOM-Based XSS.This issue affects ZoloBlocks: from n/a through <= 2.3.12. | |
| Aplazada | Media (5.3) | 0.27% | — | Sumit Singh Classic Widgets With Block Based WidgetsAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Sumit Singh Classic Widgets with Block-based Widgets classic-widgets-with-block-based-widgets allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Classic Widgets with Block-based Widgets: from n/a through <= 1.0.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Blocksera Image Hover Effects Addon FOR ElementorAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Blocksera Image Hover Effects – Elementor Addon image-hover-effects-addon-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Hover Effects – Elementor Addon: from n/a through <= 1.4.4. | |
| Aplazada | Media (6.5) | 0.27% | — | Ataur R Gutenkit Blocks AddonAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ataur R GutenKit gutenkit-blocks-addon allows Stored XSS.This issue affects GutenKit: from n/a through <= 2.4.2. |