Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1035 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (4.8) | 0.37% | — | Semalt Blocker Project Semalt Blocker | 10/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss Semalt Blocker plugin <= 1.1.3 versions. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Blockchain Keystore | 4/5/2023 | 17/6/2026 | Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code. | |
| Modificada | Media (5.4) | 0.36% | — | Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager | 3/5/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions. | |
| Modificada | Media (4.3) | 0.55% | — | Creativethemes Blocksy Companion | 2/5/2023 | 17/6/2026 | The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example | |
| Modificada | Media (6.5) | 0.29% | — | Epiph Form Block | 20/4/2023 | 17/6/2026 | Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to the forms from any website without a… | |
| Modificada | Alta (8.8) | 1.5% | — | Crocoblock Jetengine FOR Elementor | 10/4/2023 | 17/6/2026 | The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability. | |
| Modificada | Media (5.4) | 0.34% | — | Creativethemes Blocksy Companion | 6/4/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions. | |
| Modificada | Media (4.3) | 0.28% | — | Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks | 27/3/2023 | 17/6/2026 | The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack | |
| Modificada | Alta (8.1) | 0.73% | — | Simplygallery Simply Gallery Blocks With Lightbox | 27/3/2023 | 17/6/2026 | The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a… | |
| Modificada | Media (6.1) | 0.46% | — | Blockonomics | 23/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3.5.7 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Kesz1 Ipblocklist | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Kesz1 Technologies ipBlockList plugin <= 1.0 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions. | |
| Modificada | Alta (8.8) | 0.28% | — | DH - Anti Adblocker Project DH - Anti Adblocker | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions. | |
| Modificada | Alta (7.5) | 0.86% | — | Getadmiral AD Blocking Detector | 10/3/2023 | 17/6/2026 | A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 1.2.2 is able… | |
| Modificada | Media (5.4) | 0.47% | — | Donation Block FOR Paypal Project Donation Block FOR Paypal | 27/2/2023 | 17/6/2026 | The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.48% | — | Crocoblock Jetwidgets FOR Elementor | 13/2/2023 | 17/6/2026 | The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.47% | — | Brave Adblock-lists | 9/2/2023 | 17/6/2026 | Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This could potentially cause open redirects on these websites. Brave's redirect… | |
| Modificada | Media (5.4) | 0.38% | — | Openedx Xblock-lti-consumer | 26/1/2023 | 17/6/2026 | LTI Consumer XBlock implementa el lado del consumidor de la especificación LTI, lo que permite la integración de herramientas de proveedores de LTI de terceros. Las versiones 7.0.0 y superiores, anteriores a la 7.2.2, son vulnerables a la falta de autorización. Cualquier herramienta LTI integrada en la plataforma Open… | |
| Modificada | Media (6.5) | 0.33% | — | Crocoblock Jetwidgets FOR Elementor | 5/1/2023 | 17/6/2026 | El complemento JetWidgets for Elementor para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 1.0.12 incluida. Esto se debe a que falta la validación nonce en la función save(). Esto hace posible que atacantes no autenticados modifiquen la configuración del complemento mediante una solicitud… |