Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.65% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations. | |
| Aplazada | Alta (7.5) | 0.31% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details. | |
| Aplazada | Alta (7) | 0.17% | — | Block GooseAI | 10/8/2026 | 9/9/2026 | goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious repository whose `.git/config` sets [`core] fsmonitor = <command>` causes Git to… | |
| Aplazada | Media (5.4) | 0.28% | — | Block User AccountAI | 10/8/2026 | 26/8/2026 | The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API. | |
| Aplazada | Media (6.1) | 0.27% | — | Crocoblock JetengineAI | 10/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Aplazada | Media (5.3) | 0.32% | — | Lock-upme OpmsAI | 9/8/2026 | 12/8/2026 | A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql injection. The attack is possible to be… | |
| Aplazada | Baja (3.8) | 0.17% | — | Posimyth Nexter BlocksAI | 9/8/2026 | 26/8/2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not restrict who can save global CSS through one of its REST endpoints, allowing users with at least the Contributor role to store arbitrary CSS that is rendered site-wide on the front end, enabling defacement, content hiding, and UI redressing. | |
| Aplazada | Media (4.3) | 0.29% | — | Kadence BlocksAI | 6/8/2026 | 12/8/2026 | Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JetformbuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | |
| Aplazada | Media (5) | 0.14% | — | Tubitak Bilgem Eta-otp-lockAI | 6/8/2026 | 26/8/2026 | Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdeveloper Essential BlocksAI | 6/8/2026 | 26/8/2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site registered as non-public. | |
| Aplazada | Alta (7.5) | 1.5% | — | Gutenberg Essential BlocksAI | 6/8/2026 | 26/8/2026 | The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold for any published product. | |
| Aplazada | Media (6.1) | 0.25% | — | Posimyth Nexter BlocksAI | 6/8/2026 | 29/9/2026 | The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to Stored Cross-Site Scripting. | |
| Aplazada | Alta (8) | 0.46% | — | Create BlockAI | 4/8/2026 | 26/8/2026 | The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, allowing a multisite subsite administrator (who holds the capability gating this action but is denied the capability that normally gates PHP file editing) to inject and… | |
| Aplazada | Alta (7.8) | 0.37% | — | Tubitak Bilgem Eta-otp-lockAI | 3/8/2026 | 26/8/2026 | Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4. | |
| Aplazada | Media (5.1) | 0.24% | — | Luci-app-adblock-fastAI | 2/8/2026 | 9/9/2026 | luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin. | |
| Aplazada | Media (5.4) | 0.23% | — | Crocoblock JetengineAI | 2/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators. | |
| Aplazada | Media (6.4) | 0.33% | — | Kadence BlocksAI | 1/8/2026 | 12/8/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Block Attribute in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.36% | — | Kadence BlocksAI | 1/8/2026 | 12/8/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block Inner Image Content in all versions up to, and including, 3.7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.33% | — | Cozythemes Cozy BlocksAI | 1/8/2026 | 12/8/2026 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'layoutCircle.alignment' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping.… | |
| Aplazada | Media (6.4) | 0.42% | — | GenerateblocksAI | 1/8/2026 | 12/8/2026 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Dynamic Tag Injection in HTML Attributes in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Pendiente de análisis | Media (4.7) | 0.11% | — | NtpsecAIZyfer RefclockAI | 31/7/2026 | 28/8/2026 | Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd | |
| Aplazada | Alta (7.1) | 0.19% | — | Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+25 | 30/7/2026 | 18/9/2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,… | |
| Aplazada | Media (6.5) | 1.6% | — | DrivelockAI | 29/7/2026 | 30/7/2026 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port… |