Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)1.3%💥 ExploitIp2location Country Blocker22/2/202517/6/2026
The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings.
AplazadaMedia (6.5)0.23%—Cheesefather Botnet Attack BlockerAI16/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botnet Attack Blocker botnet-attack-blocker allows Stored XSS.This issue affects Botnet Attack Blocker: from n/a through <= 2.0.0.
AnalizadaMedia (6.1)0.29%—Mr-kalathiya WP Contect Form7 Email Spam Blocker25/1/202517/6/2026
The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
ModificadaMedia (4.8)0.31%—Ip2location Country Blocker24/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker ip2location-country-blocker allows Stored XSS.This issue affects Download IP2Location Country Blocker: from n/a through <= 2.38.3.
AplazadaAlta (7.1)0.34%—Adworkmedia Adwork Media EZ Content LockerAI2/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adworkmedia AdWork Media EZ Content Locker adwork-media-ez-content-locker allows Reflected XSS.This issue affects AdWork Media EZ Content Locker: from n/a through <= 3.0.
AplazadaMedia (5.3)0.35%—Dogblocker Minify HtmlAI13/12/202417/6/2026
The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is due to processing user-supplied input as a regular expression. This makes it possible for unauthenticated attackers to create comments that can cause catastrophic…
AplazadaMedia (6.1)0.39%—Ip2location Country BlockerAI12/12/202417/6/2026
The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaAlta (7.1)0.20%—Ip2location Country BlockerAI9/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker: from n/a through <= 3.2.
AnalizadaMedia (4.8)0.38%—Netfunkdesign Adbuddy+ (adblocker Detection)28/11/202417/6/2026
The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AplazadaMedia (6.5)0.43%—Pluginops Social LockerAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Social Locker social-locker-content allows Stored XSS.This issue affects Social Locker: from n/a through <= 1.1.
AplazadaMedia (4.3)0.21%—Decentralizejustice AnonymouslockerAIDecentralizejustice AnonbackendAI13/6/202417/6/2026
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.
AplazadaMedia (6.5)0.39%—Annonshop APPAIDecentralizejustice AnonymouslockerAI13/6/202417/6/2026
An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.
AnalizadaMedia (5.3)0.42%—Ip2location Country Blocker4/6/202417/6/2026
Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1.
AplazadaMedia (5.3)0.54%—Lionscripts IP Blocker LiteAI17/5/202417/6/2026
Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1.
ModificadaAlta (8.8)0.24%—Ip2location Country Blocker15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2.
ModificadaAlta (7.5)0.45%—Ip2location Country Blocker24/1/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.
ModificadaAlta (7.2)0.69%—Solwininfotech User Blocker7/11/202317/6/2026
Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.
ModificadaAlta (8.8)0.31%—Lionscripts IP Blocker Lite10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.
ModificadaCrítica (9.8)0.58%—Applika Call Blocker30/5/202317/6/2026
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
ModificadaCrítica (9.8)1.2%—Applika Call Blocker30/5/202317/6/2026
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of…
ModificadaAlta (7.5)1.2%—Applika Call Blocker30/5/202317/6/2026
The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker injects too much data, the application…
ModificadaAlta (8.8)0.26%—Dogblocker Minify Html23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.
ModificadaAlta (8.8)0.26%—Dogblocker Read More Excerpt Link23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Read More Excerpt Link plugin <= 1.6 versions.
ModificadaMedia (4.8)0.37%—Semalt Blocker Project Semalt Blocker10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss Semalt Blocker plugin <= 1.1.3 versions.
ModificadaCrítica (9.1)1.0%—Phpgurukul Bank Locker Management System9/4/202317/6/2026
A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The…
Orbitaley — Vulnerabilidades