Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.25% | — | Wpdive Nexa BlocksAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdive Nexa Blocks nexa-blocks allows Stored XSS.This issue affects Nexa Blocks: from n/a through <= 1.1.0. | |
| Aplazada | Media (6.5) | 0.25% | — | Stiofan Blockstrap Page Builder BlocksAI | 6/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks blockstrap-page-builder-blocks allows Stored XSS.This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through <= 0.1.36. | |
| Aplazada | Media (5.4) | 0.19% | — | Anti Spam Spam Protection Block Spam Users Comments FormsAI | 6/6/2025 | 17/6/2026 | The Anti-Spam: Spam Protection | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2024.7. This is due to missing or incorrect nonce validation in the 'ss_option_maint.php' and 'ss_user_filter_list' files. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.29% | — | Themehunk Vayu BlocksAI | 3/6/2025 | 17/6/2026 | The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘containerWidth’ parameter in all versions up to, and including, 1.3.1 due to a missing capability check on the vayu_blocks_option_panel_callback() function and insufficient input… | |
| Aplazada | Alta (8.3) | 0.20% | — | Kruger Matz SmartphoneAISpsoftmobile ApplockAI | 30/5/2025 | 17/6/2026 | An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.pri.applock.LockUI“ activity allows any other malicious application, with no granted Android system permissions, to inject an… | |
| Aplazada | Media (6.9) | 0.18% | — | Spsoftmobile ApplockAI | 30/5/2025 | 17/6/2026 | An application "com.pri.applock", which is pre-loaded on Kruger&Matz smartphones, allows a user to encrypt any application using user-provided PIN code or by using biometric data. Exposed ”com.android.providers.settings.fingerprint.PriFpShareProvider“ content provider's public method query() allows any other malicious… | |
| Modificada | Crítica (9.1) | 0.46% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 5/7/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication. | |
| Analizada | Alta (7.5) | 0.24% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 17/6/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext. | |
| Analizada | Media (5.9) | 0.19% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 17/6/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack. | |
| Aplazada | Media (6.4) | 0.41% | — | MAP Block LeafletAI | 29/5/2025 | 17/6/2026 | The Map Block Leaflet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Media (6.4) | 0.35% | — | Wpdeveloper Essential BlocksAI | 27/5/2025 | 17/6/2026 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML attributes in Slider and Post Carousel widgets in all versions up to, and including, 5.4.0 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Crítica (9.8) | 0.27% | — | Tickbh Process Lock | 24/5/2025 | 17/6/2026 | The process_lock crate 0.1.0 for Rust allows data races in unlock. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock Jetblocks FOR ElementorAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetBlocks For Elementor: from n/a through <= 1.3.16. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JET WOO BuilderAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetWooBuilder: from n/a through <= 2.1.18. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock Jetelements FOR ElementorAI | 19/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Crocoblock JetElements For Elementor jet-elements allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JetElements For Elementor: from n/a through <= 2.7.4.1. | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock JettabsAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs jet-tabs allows DOM-Based XSS.This issue affects JetTabs: from n/a through <= 2.2.7. | |
| Aplazada | Media (6.5) | 0.21% | — | Crocoblock Jetelements FOR ElementorAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.4.1. | |
| Aplazada | Alta (7.5) | 0.61% | — | Crocoblock JetreviewsAI | 19/5/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Crocoblock JetReviews jet-reviews allows PHP Local File Inclusion.This issue affects JetReviews: from n/a through <= 2.3.6. | |
| Modificada | Media (5.4) | 0.21% | — | Sktthemes SKT Blocks | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Blocks skt-blocks allows DOM-Based XSS.This issue affects SKT Blocks: from n/a through <= 2.2. | |
| Aplazada | Media (6.5) | 0.29% | — | Dotcamp Ultimate BlocksAI | 19/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ultimate Blocks Ultimate Blocks ultimate-blocks allows DOM-Based XSS.This issue affects Ultimate Blocks: from n/a through <= 3.3.0. | |
| Modificada | Media (5.4) | 0.24% | — | Qodeinteractive QI Blocks | 19/5/2025 | 17/6/2026 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.24% | — | Qodeinteractive QI Blocks | 19/5/2025 | 17/6/2026 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Countdown block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.28% | — | Qodeinteractive QI Blocks | 19/5/2025 | 17/6/2026 | The Qi Blocks WordPress plugin before 1.4 does not validate and escape some of its Counter block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Analizada | Media (5.5) | 0.42% | — | Lirantal Lockfile-lint-api | 16/5/2025 | 17/6/2026 | Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one. | |
| Analizada | Media (6.1) | 0.18% | — | Justintadlock Javascript-logic | 15/5/2025 | 17/6/2026 | The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. |