Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | Cyberchimps Responsive BlocksAI | 27/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows DOM-Based XSS.This issue affects Responsive Blocks: from n/a through <= 2.0.6. | |
| Modificada | Media (5.4) | 0.25% | — | Osompress Osom Blocks | 27/6/2025 | 17/6/2026 | The Osom Blocks – Custom Post Type listing block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class_name’ parameter in all versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.8) | 0.24% | — | WP MAP Block Project WP MAP Block | 27/6/2025 | 17/6/2026 | The WP Map Block WordPress plugin before 2.0.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Baja (2.4) | 0.15% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code. | |
| Analizada | Media (4.6) | 0.24% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system. | |
| Analizada | Media (6.8) | 0.25% | — | Flocksafety License Plate Reader Firmware | 27/6/2025 | 17/6/2026 | Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control. | |
| Analizada | Media (4.6) | 0.23% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system. | |
| Analizada | Baja (2.4) | 0.16% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code. | |
| Analizada | Media (6.8) | 0.26% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control. | |
| Analizada | Media (4.6) | 0.24% | — | Flocksafety Gunshot Detection Firmware | 27/6/2025 | 17/6/2026 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection. | |
| Aplazada | Media (6.5) | 0.23% | — | Wpengine Gutenberg Blocks ACF Blocks SuiteAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Engine Gutenberg Blocks – ACF Blocks Suite acf-blocks allows Stored XSS.This issue affects Gutenberg Blocks – ACF Blocks Suite: from n/a through <= 2.6.11. | |
| Aplazada | Media (6.5) | 0.32% | — | Mahmudul Hasan Arif Enhanced BlocksAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Mahmudul Hasan Arif Enhanced Blocks – Page Builder Blocks for Gutenberg enhanced-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Enhanced Blocks – Page Builder Blocks for Gutenberg: from n/a through <= 1.4.1. | |
| Aplazada | Media (5.9) | 0.26% | — | Chris Coyier Codepen Embed BlockAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Coyier CodePen Embed Block codepen-embed-block allows Stored XSS.This issue affects CodePen Embed Block: from n/a through <= 1.2.0. | |
| Aplazada | Alta (7) | 0.47% | 💥 PoC | LibblockdevAIFreedesktop UdisksAI | 19/6/2025 | 30/6/2026 | A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able… | |
| Aplazada | Media (6.5) | 0.19% | — | Cyberchimps Responsive BlocksAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Responsive Blocks responsive-block-editor-addons allows Stored XSS.This issue affects Responsive Blocks: from n/a through <= 2.0.5. | |
| Aplazada | Media (6.4) | 0.27% | — | Game Review BlockAI | 13/6/2025 | 17/6/2026 | The Game Review Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 4.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (5.4) | 0.25% | — | Janboddez Indieblocks | 13/6/2025 | 17/6/2026 | The IndieBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘kind’ parameter in all versions up to, and including, 0.13.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (5.3) | 0.27% | — | Quick Node Block Project Quick Node Block | 11/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. | |
| Analizada | Media (5.3) | 0.27% | — | Quick Node Block Project Quick Node Block | 11/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Quick Node Block allows Forceful Browsing.This issue affects Quick Node Block: from 0.0.0 before 2.0.0. | |
| Analizada | Media (5.4) | 0.26% | — | Dotcamp Ultimate Blocks | 10/6/2025 | 17/6/2026 | The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Alta (7.5) | 0.50% | — | Spicethemes Spice BlocksAI | 9/6/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks spice-blocks allows Path Traversal.This issue affects Spice Blocks: from n/a through <= 2.0.7.4. | |
| Aplazada | Alta (8.8) | 0.32% | — | Christiaan Pieterse Maxi-blocksAI | 7/6/2025 | 17/6/2026 | Missing Authorization vulnerability in Christiaan Pieterse MaxiBlocks maxi-blocks allows Privilege Escalation.This issue affects MaxiBlocks: from n/a through <= 2.1.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Wpsoul Greenshift Animation AND Page Builder BlocksAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows DOM-Based XSS.This issue affects Greenshift: from n/a through <= 11.5.5. | |
| Aplazada | Media (6.5) | 0.25% | — | Blocksera Image Hover Effects BlockAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksera Image Hover Effects Block image-hover-effects-block allows Stored XSS.This issue affects Image Hover Effects Block: from n/a through <= 1.4.5. | |
| Aplazada | Media (4.9) | 0.22% | — | Wpdive Nexa BlocksAI | 6/6/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in wpdive Nexa Blocks nexa-blocks allows Server Side Request Forgery.This issue affects Nexa Blocks: from n/a through <= 1.1.1. |