Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.39%—Cozythemes Cozy BlocksAI1/9/20261/9/2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaMedia (4.6)0.16%—Iobit UnlockerAI31/8/202631/8/2026
A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was…
AplazadaAlta (7.1)0.60%—Powsybl Power System BlocksAI28/8/20269/9/2026
PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without sufficient escaping. Attacker-controlled…
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI28/8/202628/8/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
AplazadaCrítica (9.8)2.9%—23blocks-os Ai-maestroAI28/8/20269/9/2026
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
AplazadaMedia (6.4)0.36%—Greenshift Animation AND Page Builder BlocksAI26/8/202626/8/2026
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up to, and including, 12.8.9. This is due to insufficient sanitization of API responses before output via innerHTML. This makes it possible for authenticated…
AplazadaMedia (6.4)0.35%—Gutenverse Ultimate Wordpress FSE Blocks Addons EcosystemAI26/8/202626/8/2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.35%—Cozythemes Cozy BlocksAI25/8/202626/8/2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via cozyHoverEffect Block Attribute in all versions up to, and including, 2.2.16 due to insufficient input sanitization and output escaping. This makes…
AplazadaAlta (7.1)0.25%—Renzojohnson BlocksAI24/8/202626/8/2026
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
AplazadaAlta (8.8)0.65%—RansomlockAI24/8/202626/8/2026
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources. For local authentication, the login implementation previously checked…
AplazadaCrítica (9.2)0.69%—RansomlockAI24/8/202626/8/2026
RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated remote users to retrieve information intended to remain private. The /export/<database> endpoint permits selected internal databases to be exported without requiring authentication. While limited…
AplazadaMedia (6.5)0.22%—Themegrill Magazine BlocksAI24/8/202624/8/2026
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI20/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions.
AplazadaCrítica (9.8)0.86%—Crocoblock JetengineAI19/8/202620/8/2026
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
AplazadaMedia (6.8)0.43%—Crocoblock JetengineAI19/8/202626/8/2026
The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored…
AplazadaAlta (7.1)0.25%—Recipe Card Blocks FOR Gutenberg AND ElementorAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in Recipe Card Blocks for Gutenberg & Elementor <= 3.4.18 versions.
AplazadaMedia (6.5)0.22%—Table OF Contents BlockAI18/8/202620/8/2026
Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.
AplazadaBaja (2.1)0.42%—Adblock FOR YoutubeAI17/8/202620/8/2026
A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to…
AplazadaCrítica (9.1)0.20%—Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
AplazadaAlta (8.4)0.14%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high…
AplazadaAlta (7.5)0.49%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
AplazadaCrítica (9.8)0.78%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
AplazadaMedia (4.6)0.24%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
AplazadaAlta (7.2)0.67%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high…
AplazadaAlta (7.5)0.19%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.