Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
AplazadaAlta (7.5)0.32%—Crocoblock JetengineAI17/6/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202628/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI25/5/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.
AplazadaMedia (5.5)0.79%—Crocodilestick Calibre-web-automatedAI4/5/202617/6/2026
A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been…
AplazadaBaja (2.1)0.46%—Crocodilestick Calibre-web-automatedAI4/5/202617/6/2026
A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The…
AplazadaMedia (5.3)0.22%—Ribblr Crochet KnittingAI27/4/20267/10/2026
Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application
AnalizadaAlta (8.7)0.23%—Microchip Istax16/4/202612/8/2026
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.
AplazadaAlta (7.5)0.46%—Crocoblock JetengineAI14/4/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of…
AnalizadaMedia (5.5)0.32%—Microchip Timeprovider 4100 Firmware28/3/202612/8/2026
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0.
AplazadaMedia (5.5)0.41%—Streamax CrocusAI27/3/202617/6/2026
A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter Handler. The manipulation of the argument State results in sql injection. The attack can be launched remotely. The…
AplazadaMedia (5.5)0.41%—Streamax CrocusAI27/3/202617/6/2026
A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor…
AplazadaMedia (5.5)0.41%—Streamax CrocusAI27/3/202617/6/2026
A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely. The exploit has…
AplazadaCrítica (9.9)0.52%—Crocoblock JetformbuilderAI25/3/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1.
AplazadaAlta (7.5)0.54%—Crocoblock JetengineAI24/3/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks)…
AplazadaAlta (7.5)0.57%—Crocoblock JetformbuilderAI21/3/202617/6/2026
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs…
AplazadaAlta (8.8)0.52%—Crocoblock JetengineAI13/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1.
AplazadaAlta (8.5)0.40%💥 PoCCrocoblock JetengineAI5/3/202617/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2.
AnalizadaCrítica (9.3)0.26%—Microchip Timepictra28/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2.
AnalizadaCrítica (9.3)0.44%—Microchip Timepictra28/2/202617/6/2026
Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2.
ModificadaMedia (5.7)0.10%—Microchip Timeprovider 4100 Firmware24/2/202617/6/2026
Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.
AplazadaAlta (7.1)0.19%—Crocoblock JetengineAI20/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0.
AnalizadaMedia (6.9)0.42%—Microcom360 Zeusweb11/2/202617/6/2026
Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Application Fingerprinting of sensitive data. This issue affects ZeusWeb: 6.1.31.
AnalizadaMedia (5.1)0.24%—Microcom360 Zeusweb11/2/202617/6/2026
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Surname’ parameter of the ‘Create Account’ operation…
AnalizadaMedia (5.1)0.24%—Microcom360 Zeusweb11/2/202617/6/2026
An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Email’ parameters within the ‘Recover password’…
Orbitaley — Vulnerabilidades