Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1035 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.8)0.37%—Semalt Blocker Project Semalt Blocker10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss Semalt Blocker plugin <= 1.1.3 versions.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaMedia (5.4)0.36%—Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager3/5/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
ModificadaMedia (4.3)0.55%—Creativethemes Blocksy Companion2/5/202317/6/2026
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
ModificadaMedia (6.5)0.29%—Epiph Form Block20/4/202317/6/2026
Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to the forms from any website without a…
ModificadaAlta (8.8)1.5%—Crocoblock Jetengine FOR Elementor10/4/202317/6/2026
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
ModificadaMedia (5.4)0.34%—Creativethemes Blocksy Companion6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaAlta (8.1)0.73%—Simplygallery Simply Gallery Blocks With Lightbox27/3/202317/6/2026
The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a…
ModificadaMedia (6.1)0.46%—Blockonomics23/3/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Blockonomics WordPress Bitcoin Payments – Blockonomics plugin <= 3.5.7 versions.
ModificadaAlta (8.8)0.27%—Kesz1 Ipblocklist14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kesz1 Technologies ipBlockList plugin <= 1.0 versions.
ModificadaAlta (8.8)0.26%—Piwebsolution CSS JS Manager, Async Javascript, Defer Render Blocking CSS Supports Woocommerce14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.
ModificadaAlta (8.8)0.28%—DH - Anti Adblocker Project DH - Anti Adblocker14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions.
ModificadaAlta (7.5)0.86%—Getadmiral AD Blocking Detector10/3/202317/6/2026
A vulnerability has been found in Ad Blocking Detector Plugin up to 1.2.1 on WordPress and classified as problematic. This vulnerability affects unknown code of the file ad-blocking-detector.php. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 1.2.2 is able…
ModificadaMedia (5.4)0.47%—Donation Block FOR Paypal Project Donation Block FOR Paypal27/2/202317/6/2026
The Donation Block For PayPal WordPress plugin before 2.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (5.4)0.48%—Crocoblock Jetwidgets FOR Elementor13/2/202317/6/2026
The JetWidgets For Elementor WordPress plugin before 1.0.14 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.1)0.47%—Brave Adblock-lists9/2/202317/6/2026
Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may have been there for security purposes. This could potentially cause open redirects on these websites. Brave's redirect…
ModificadaMedia (5.4)0.38%—Openedx Xblock-lti-consumer26/1/202317/6/2026
LTI Consumer XBlock implementa el lado del consumidor de la especificación LTI, lo que permite la integración de herramientas de proveedores de LTI de terceros. Las versiones 7.0.0 y superiores, anteriores a la 7.2.2, son vulnerables a la falta de autorización. Cualquier herramienta LTI integrada en la plataforma Open…
ModificadaMedia (6.5)0.33%—Crocoblock Jetwidgets FOR Elementor5/1/202317/6/2026
El complemento JetWidgets for Elementor para WordPress es vulnerable a Cross-Site Request Forgery en versiones hasta la 1.0.12 incluida. Esto se debe a que falta la validación nonce en la función save(). Esto hace posible que atacantes no autenticados modifiquen la configuración del complemento mediante una solicitud…