Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
264 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1. | |
| Aplazada | Media (5.5) | 0.79% | — | Crocodilestick Calibre-web-automatedAI | 4/5/2026 | 17/6/2026 | A flaw has been found in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this issue is some unknown functionality of the file cps/cwa_functions.py of the component Admin Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.46% | — | Crocodilestick Calibre-web-automatedAI | 4/5/2026 | 17/6/2026 | A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The… | |
| Aplazada | Media (5.3) | 0.22% | — | Ribblr Crochet KnittingAI | 27/4/2026 | 7/10/2026 | Authenticated user can bypass authorization in Ribblr - Crochet & Knitting iOS application | |
| Analizada | Alta (8.7) | 0.23% | — | Microchip Istax | 16/4/2026 | 12/8/2026 | A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03. | |
| Aplazada | Alta (7.5) | 0.46% | — | Crocoblock JetengineAI | 14/4/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of… | |
| Analizada | Media (5.5) | 0.32% | — | Microchip Timeprovider 4100 Firmware | 28/3/2026 | 12/8/2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5.0. | |
| Aplazada | Media (5.5) | 0.41% | — | Streamax CrocusAI | 27/3/2026 | 17/6/2026 | A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter Handler. The manipulation of the argument State results in sql injection. The attack can be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Streamax CrocusAI | 27/3/2026 | 17/6/2026 | A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor… | |
| Aplazada | Media (5.5) | 0.41% | — | Streamax CrocusAI | 27/3/2026 | 17/6/2026 | A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an unknown function of the file /RemoteFormat.do of the component Endpoint. Such manipulation of the argument State leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Crocoblock JetformbuilderAI | 25/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through <= 3.5.6.1. | |
| Aplazada | Alta (7.5) | 0.54% | — | Crocoblock JetengineAI | 24/3/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the `listing_load_more` AJAX action in all versions up to, and including, 3.8.6.1. This is due to the `filtered_query` parameter being excluded from the HMAC signature validation (allowing attacker-controlled input to bypass security checks)… | |
| Aplazada | Alta (7.5) | 0.57% | — | Crocoblock JetformbuilderAI | 21/3/2026 | 17/6/2026 | The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 3.5.6.2. This is due to the 'Uploaded_File::set_from_array' method accepting user-supplied file paths from the Media Field preset JSON payload without validating that the path belongs… | |
| Aplazada | Alta (8.8) | 0.52% | — | Crocoblock JetengineAI | 13/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Crocoblock JetEngine jet-engine allows Object Injection.This issue affects JetEngine: from n/a through < 3.8.4.1. | |
| Aplazada | Alta (8.5) | 0.40% | 💥 PoC | Crocoblock JetengineAI | 5/3/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetEngine jet-engine allows Remote Code Inclusion.This issue affects JetEngine: from n/a through <= 3.7.2. | |
| Analizada | Crítica (9.3) | 0.26% | — | Microchip Timepictra | 28/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimePictra allows Query System for Information.This issue affects TimePictra: from 11.0 through 11.3 SP2. | |
| Analizada | Crítica (9.3) | 0.44% | — | Microchip Timepictra | 28/2/2026 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Microchip TimePictra allows Configuration/Environment Manipulation.This issue affects TimePictra: from 11.0 through 11.3 SP2. | |
| Modificada | Media (5.7) | 0.10% | — | Microchip Timeprovider 4100 Firmware | 24/2/2026 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This issue affects Time Provider 4100: before 2.5. | |
| Aplazada | Alta (7.1) | 0.19% | — | Crocoblock JetengineAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0. | |
| Analizada | Media (6.9) | 0.42% | — | Microcom360 Zeusweb | 11/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Actor vulnerability in Microcom ZeusWeb allows Web Application Fingerprinting of sensitive data. This issue affects ZeusWeb: 6.1.31. | |
| Analizada | Media (5.1) | 0.24% | — | Microcom360 Zeusweb | 11/2/2026 | 17/6/2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Surname’ parameter of the ‘Create Account’ operation… | |
| Analizada | Media (5.1) | 0.24% | — | Microcom360 Zeusweb | 11/2/2026 | 17/6/2026 | An attacker with access to the web application ZeusWeb of the provider Microcom (in this case, registration is not necessary, but the action must be performed) who has the vulnerable software could introduce arbitrary JavaScript by injecting an XSS payload into the ‘Email’ parameters within the ‘Recover password’… |