Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.42% | — | GenerateblocksAI | 1/8/2026 | 12/8/2026 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (4.3) | 0.34% | — | Survey Form BlockAI | 29/7/2026 | 30/7/2026 | The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey… | |
| Aplazada | Media (6.4) | 0.43% | — | Cozythemes Cozy BlocksAI | 28/7/2026 | 28/7/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This… | |
| Aplazada | Media (6.5) | 0.22% | — | Gallery PhotoblocksAI | 27/7/2026 | 27/7/2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions. | |
| Aplazada | Media (5.4) | 0.22% | — | Affiliatexblocks AffiliatexAI | 27/7/2026 | 27/7/2026 | Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions. | |
| Aplazada | Media (6.4) | 0.43% | — | Cozythemes Cozy BlocksAI | 24/7/2026 | 24/7/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Media (6.4) | 0.43% | — | Cozythemes Cozy BlocksAI | 24/7/2026 | 24/7/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes… | |
| Aplazada | Media (4.3) | 0.86% | — | Posimyth Nexter BlocksAI | 24/7/2026 | 24/7/2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary… | |
| Aplazada | Media (6.4) | 0.33% | — | Postx Post Grid Gutenberg BlocksAI | 24/7/2026 | 24/7/2026 | The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.9) | 0.19% | — | Crocoblock JetengineAI | 23/7/2026 | 23/7/2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock Jetelements FOR ElementorAI | 23/7/2026 | 23/7/2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. | |
| Aplazada | Media (4.4) | 0.21% | — | Photo BlockAI | 23/7/2026 | 23/7/2026 | Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions. | |
| Aplazada | Media (6.4) | 0.32% | — | Spectra Gutenberg BlocksAI | 20/7/2026 | 22/7/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.3) | 0.39% | — | Fense Proxy VPN BlockerAI | 17/7/2026 | 21/7/2026 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*… | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JetsearchAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2. | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock Jetblocks FOR ElementorAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0. | |
| Aplazada | Media (5.3) | 0.33% | — | Crocoblock JET ReviewsAI | 13/7/2026 | 13/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Proxy & VPN BlockerAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.8. | |
| Aplazada | Alta (8.8) | 0.42% | — | Tusharimran AblocksAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1. | |
| Aplazada | Media (6.4) | 0.45% | — | Simply Gallery BlockAI | 11/7/2026 | 13/7/2026 | The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2. This is due to insufficient input sanitization and output escaping on the sliderMaxHeight block attribute in the pgc_sgb_render_callback() function.… | |
| Aplazada | Media (4.4) | 0.34% | — | Highlighting Code BlockAI | 10/7/2026 | 10/7/2026 | The Highlighting Code Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… | |
| Aplazada | Media (4.3) | 0.37% | — | Kadencewp Gutenberg Blocks With AIAI | 10/7/2026 | 10/7/2026 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to unauthorized post publication in all versions up to, and including, 3.5.32 due to a misconfigured capability check on the 'get_items_permission_check' function permission callback of the 'process_pattern' REST API… | |
| Aplazada | Media (6.5) | 0.47% | — | Blocks FOR ACF FieldsAI | 9/7/2026 | 9/7/2026 | The Blocks for ACF Fields plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_values() function in the /wp-json/acf-field-blocks/v1/values REST endpoint in versions up to, and including, 1.6.2. The permission_callback only verifies the generic… | |
| Aplazada | Crítica (9.8) | 1.1% | — | Creativethemes Blocksy CompanionAI | 9/7/2026 | 9/7/2026 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring… |