Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.
AplazadaMedia (5.4)0.23%—Crocoblock JetengineAI2/8/202626/8/2026
The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators.
AplazadaMedia (4.9)0.19%—Crocoblock JetengineAI23/7/202623/7/2026
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
AplazadaCrítica (9.8)0.56%—CrocusAI21/7/202622/7/2026
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper.xml file
AplazadaCrítica (9.8)0.56%—CrocusAI21/7/202622/7/2026
SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper.xml file
AplazadaMedia (5.3)0.33%—Crocoblock JetsearchAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
AplazadaMedia (5.3)0.33%—Crocoblock Jetblocks FOR ElementorAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.
AplazadaMedia (5.3)0.33%—Crocoblock JET ReviewsAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
AplazadaMedia (5.3)0.58%—Crocoblock JetformbuilderAI2/7/20262/7/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.6.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve…
AplazadaMedia (6.4)0.26%—Crocoblock Jetwidgets FOR ElementorAI1/7/20261/7/2026
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 1.0.21. This is due to insufficient output escaping and missing server-side validation of the Animated Box widget's animation_effect setting before it is rendered inside an HTML class…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI26/6/202629/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
AnalizadaMedia (5.3)0.21%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
AnalizadaMedia (5.3)0.23%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue affects GridTime 3000: from 1.0r0.03 before 1.2r0.0.
AnalizadaMedia (4.6)0.39%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
AnalizadaMedia (5.1)0.23%—Microchip Gridtime 3000 Firmware19/6/20269/7/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-Site Scripting (XSS). This issue affects GridTime 3000: from 1.0r0.03 through 1.1r0.0.
AplazadaMedia (5.1)0.30%—Canonical MicrocephAI19/6/202622/6/2026
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-import API. Holders of a trusted cluster mTLS certificate (such as enrolled cluster members) or join token can manipulate files in an imported remote cluster within the /var/snap/microceph confinement.…
AplazadaMedia (6.8)0.28%—Crocoblock JetformbuilderAI17/6/202616/9/2026
Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1.
AplazadaAlta (7.1)0.25%—Crocoblock JetformbuilderAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
Orbitaley — Vulnerabilidades