Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.73% | — | Phpgurukul Bank Locker Management System | 9/4/2023 | 17/6/2026 | A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Alta (8.8) | 0.28% | — | DH - Anti Adblocker Project DH - Anti Adblocker | 14/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions. | |
| Modificada | Alta (7.8) | 0.23% | — | Xoslab Easy File Locker | 18/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Xoslab Easy File Locker 2.2.0.184. This affects the function MessageNotifyCallback in the library xlkfs.sys. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and… | |
| Modificada | Media (4.8) | 38% | 💥 Exploit | Phpgurukul Bank Locker Management System | 28/1/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely.… | |
| Modificada | Crítica (9.8) | 44% | 💥 Exploit | Phpgurukul Bank Locker Management System | 28/1/2023 | 17/6/2026 | A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit… | |
| Modificada | Crítica (9.8) | 17% | 💥 Exploit | Pfsense Pfblockerng | 20/12/2022 | 17/6/2026 | pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. | |
| Modificada | Crítica (9.8) | 92% | 💥 Exploit | Netgate Pfblockerng | 5/9/2022 | 17/6/2026 | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected. | |
| Modificada | Media (6.7) | 0.98% | 💥 PoC | Kidan Cryptopro Securedisk FOR BitlockerRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+6 | 26/8/2022 | 17/6/2026 | A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this… | |
| Modificada | Alta (8.1) | 0.39% | — | Softcreate L2blocker | 27/6/2022 | 17/6/2026 | Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by using alternative paths or channels for… | |
| Modificada | Media (6.5) | 0.53% | — | Byonepress Social Locker | 13/6/2022 | 17/6/2026 | The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Alta (7.1) | 0.45% | — | Ip2location Country Blocker | 7/2/2022 | 17/6/2026 | The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend. | |
| Modificada | Media (6.5) | 1.0% | — | Ip2location Country Blocker | 7/2/2022 | 17/6/2026 | The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL | |
| Modificada | Alta (7.1) | 0.54% | — | Ip2location Country Blocker | 7/2/2022 | 17/6/2026 | The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from… | |
| Modificada | Media (5.5) | 0.44% | — | Gglocker Project Gglocker | 16/12/2021 | 17/6/2026 | GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass. | |
| Modificada | Media (4.6) | 0.32% | — | Oneplus APP Locker | 9/10/2020 | 17/6/2026 | OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked. | |
| Modificada | Alta (7.8) | 0.63% | — | Iobit Unlocker | 23/6/2020 | 17/6/2026 | The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code 0x222124. | |
| Modificada | Alta (7.1) | 0.91% | 💥 PoC | Iobit Unlocker | 23/6/2020 | 17/6/2026 | The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124. | |
| Modificada | Media (5.4) | 0.68% | — | Byonepress Social Locker | 26/9/2019 | 17/6/2026 | The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Ht2labs Learning Locker | 16/7/2019 | 17/6/2026 | In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI. | |
| Modificada | Media (5.3) | 0.68% | — | O.bike Smart Locker FirmwareO.bike Obike-stationless Bike Sharing | 14/9/2018 | 17/6/2026 | oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol. | |
| Modificada | Alta (7.5) | 1.2% | — | Photo,video Locker-calculator Project Photo,video Locker-calculator | 20/2/2018 | 17/6/2026 | smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN. | |
| Modificada | Alta (7.5) | 0.64% | — | Photo,video Locker-calculator Project Photo,video Locker-calculator | 20/2/2018 | 17/6/2026 | The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command. | |
| Modificada | Media (6.8) | 0.44% | — | KDE KscreenlockerKDE Plasma-workspaceFedoraproject FedoraOpensuse Leap | 23/12/2016 | 17/6/2026 | Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again. | |
| Modificada | Media (5.4) | 0.27% | — | RIX GO Locker Theme Project RIX GO Locker Theme | 9/9/2014 | 17/6/2026 | The Rix GO Locker Theme (aka com.jiubang.goscreenlock.theme.rix.getjar) application 1.20.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4) | 1.4% | — | Xythos Digital LockerXythos Enterprise Document ManagerXythos Webfile Server | 27/6/2007 | 16/6/2026 | Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution. |