Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.39% | — | Cozythemes Cozy BlocksAI | 1/9/2026 | 1/9/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (4.6) | 0.16% | — | Iobit UnlockerAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was… | |
| Aplazada | Alta (7.1) | 0.60% | — | Powsybl Power System BlocksAI | 28/8/2026 | 9/9/2026 | PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without sufficient escaping. Attacker-controlled… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 28/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | |
| Aplazada | Crítica (9.8) | 2.9% | — | 23blocks-os Ai-maestroAI | 28/8/2026 | 9/9/2026 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input. | |
| Aplazada | Media (6.4) | 0.36% | — | Greenshift Animation AND Page Builder BlocksAI | 26/8/2026 | 26/8/2026 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.35% | — | Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI | 26/8/2026 | 26/8/2026 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.35% | — | Cozythemes Cozy BlocksAI | 25/8/2026 | 26/8/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Alta (7.1) | 0.25% | — | Renzojohnson BlocksAI | 24/8/2026 | 26/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions. | |
| Aplazada | Alta (8.8) | 0.65% | — | RansomlockAI | 24/8/2026 | 26/8/2026 | RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources. For local authentication, the login implementation previously checked… | |
| Aplazada | Crítica (9.2) | 0.69% | — | RansomlockAI | 24/8/2026 | 26/8/2026 | RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<database> endpoint permits selected internal databases to be exported without requiring authentication. While limited… | |
| Aplazada | Media (6.5) | 0.22% | — | Themegrill Magazine BlocksAI | 24/8/2026 | 24/8/2026 | Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | |
| Aplazada | Crítica (9.8) | 0.86% | — | Crocoblock JetengineAI | 19/8/2026 | 20/8/2026 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Crocoblock JetengineAI | 19/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Aplazada | Alta (7.1) | 0.25% | — | Recipe Card Blocks FOR Gutenberg AND ElementorAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Table OF Contents BlockAI | 18/8/2026 | 20/8/2026 | Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions. | |
| Aplazada | Baja (2.1) | 0.42% | — | Adblock FOR YoutubeAI | 17/8/2026 | 20/8/2026 | A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| Aplazada | Alta (8.4) | 0.14% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.49% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform. | |
| Aplazada | Media (4.6) | 0.24% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. | |
| Aplazada | Alta (7.2) | 0.67% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.19% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. |