Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 1.3% | 💥 Exploit | Ip2location Country Blocker | 22/2/2025 | 17/6/2026 | The IP2Location Country Blocker plugin for WordPress is vulnerable to Regular Information Exposure in all versions up to, and including, 2.38.8 due to missing capability checks on the admin_init() function. This makes it possible for unauthenticated attackers to view the plugin's settings. | |
| Aplazada | Media (6.5) | 0.23% | — | Cheesefather Botnet Attack BlockerAI | 16/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cheesefather Botnet Attack Blocker botnet-attack-blocker allows Stored XSS.This issue affects Botnet Attack Blocker: from n/a through <= 2.0.0. | |
| Analizada | Media (6.1) | 0.29% | — | Mr-kalathiya WP Contect Form7 Email Spam Blocker | 25/1/2025 | 17/6/2026 | The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modificada | Media (4.8) | 0.31% | — | Ip2location Country Blocker | 24/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker ip2location-country-blocker allows Stored XSS.This issue affects Download IP2Location Country Blocker: from n/a through <= 2.38.3. | |
| Aplazada | Alta (7.1) | 0.34% | — | Adworkmedia Adwork Media EZ Content LockerAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adworkmedia AdWork Media EZ Content Locker adwork-media-ez-content-locker allows Reflected XSS.This issue affects AdWork Media EZ Content Locker: from n/a through <= 3.0. | |
| Aplazada | Media (5.3) | 0.35% | — | Dogblocker Minify HtmlAI | 13/12/2024 | 17/6/2026 | The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 2.1.10. This is due to processing user-supplied input as a regular expression. This makes it possible for unauthenticated attackers to create comments that can cause catastrophic… | |
| Aplazada | Media (6.1) | 0.39% | — | Ip2location Country BlockerAI | 12/12/2024 | 17/6/2026 | The Country Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ip' parameter in all versions up to, and including, 3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Alta (7.1) | 0.20% | — | Ip2location Country BlockerAI | 9/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker: from n/a through <= 3.2. | |
| Analizada | Media (4.8) | 0.38% | — | Netfunkdesign Adbuddy+ (adblocker Detection) | 28/11/2024 | 17/6/2026 | The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Aplazada | Media (6.5) | 0.43% | — | Pluginops Social LockerAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Social Locker social-locker-content allows Stored XSS.This issue affects Social Locker: from n/a through <= 1.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Decentralizejustice AnonymouslockerAIDecentralizejustice AnonbackendAI | 13/6/2024 | 17/6/2026 | An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext. | |
| Aplazada | Media (6.5) | 0.39% | — | Annonshop APPAIDecentralizejustice AnonymouslockerAI | 13/6/2024 | 17/6/2026 | An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request. | |
| Analizada | Media (5.3) | 0.42% | — | Ip2location Country Blocker | 4/6/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in IP2Location Download IP2Location Country Blocker allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Download IP2Location Country Blocker: from n/a through 2.29.1. | |
| Aplazada | Media (5.3) | 0.54% | — | Lionscripts IP Blocker LiteAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue affects IP Blocker Lite: from n/a through 11.1.1. | |
| Modificada | Alta (8.8) | 0.24% | — | Ip2location Country Blocker | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in IP2Location Download IP2Location Country Blocker.This issue affects Download IP2Location Country Blocker: from n/a through 2.34.2. | |
| Modificada | Alta (7.5) | 0.45% | — | Ip2location Country Blocker | 24/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3. | |
| Modificada | Alta (7.2) | 0.69% | — | Solwininfotech User Blocker | 7/11/2023 | 17/6/2026 | Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5. | |
| Modificada | Alta (8.8) | 0.31% | — | Lionscripts IP Blocker Lite | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions. | |
| Modificada | Crítica (9.8) | 0.58% | — | Applika Call Blocker | 30/5/2023 | 17/6/2026 | The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Applika Call Blocker | 30/5/2023 | 17/6/2026 | The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of… | |
| Modificada | Alta (7.5) | 1.2% | — | Applika Call Blocker | 30/5/2023 | 17/6/2026 | The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker injects too much data, the application… | |
| Modificada | Alta (8.8) | 0.26% | — | Dogblocker Minify Html | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability. | |
| Modificada | Alta (8.8) | 0.26% | — | Dogblocker Read More Excerpt Link | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Read More Excerpt Link plugin <= 1.6 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Semalt Blocker Project Semalt Blocker | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss Semalt Blocker plugin <= 1.1.3 versions. | |
| Modificada | Crítica (9.1) | 1.0% | — | Phpgurukul Bank Locker Management System | 9/4/2023 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The… |