Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.73%—Phpgurukul Bank Locker Management System9/4/202317/6/2026
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has…
ModificadaAlta (8.8)0.28%—DH - Anti Adblocker Project DH - Anti Adblocker14/3/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Dannie Herdyawan DH – Anti AdBlocker plugin <= 36 versions.
ModificadaAlta (7.8)0.23%—Xoslab Easy File Locker18/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in Xoslab Easy File Locker 2.2.0.184. This affects the function MessageNotifyCallback in the library xlkfs.sys. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and…
ModificadaMedia (4.8)38%💥 ExploitPhpgurukul Bank Locker Management System28/1/202317/6/2026
A vulnerability classified as problematic has been found in PHPGurukul Bank Locker Management System 1.0. This affects an unknown part of the file add-locker-form.php of the component Assign Locker. The manipulation of the argument ahname leads to cross site scripting. It is possible to initiate the attack remotely.…
ModificadaCrítica (9.8)44%💥 ExploitPhpgurukul Bank Locker Management System28/1/202317/6/2026
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php of the component Login. The manipulation of the argument username leads to sql injection. The attack may be launched remotely. The exploit…
ModificadaCrítica (9.8)17%💥 ExploitPfsense Pfblockerng20/12/202217/6/2026
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
ModificadaCrítica (9.8)92%💥 ExploitNetgate Pfblockerng5/9/202217/6/2026
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
ModificadaMedia (6.7)0.98%💥 PoCKidan Cryptopro Securedisk FOR BitlockerRedhat Enterprise LinuxMicrosoft Windows 10Microsoft Windows 11+626/8/202217/6/2026
A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this…
ModificadaAlta (8.1)0.39%—Softcreate L2blocker27/6/202217/6/2026
Authentication bypass vulnerability in the setup screen of L2Blocker(on-premise) Ver4.8.5 and earlier and L2Blocker(Cloud) Ver4.8.5 and earlier allows an adjacent attacker to perform an unauthorized login and obtain the stored information or cause a malfunction of the device by using alternative paths or channels for…
ModificadaMedia (6.5)0.53%—Byonepress Social Locker13/6/202217/6/2026
The OnePress Social Locker WordPress plugin through 5.6.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (7.1)0.45%—Ip2location Country Blocker7/2/202217/6/2026
The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_blocker_save_rules AJAX action, allowing attackers to make a logged in admin block arbitrary country, or block all of them at once, preventing users from accessing the frontend.
ModificadaMedia (6.5)1.0%—Ip2location Country Blocker7/2/202217/6/2026
The IP2Location Country Blocker WordPress plugin before 2.26.5 bans can be bypassed by using a specific parameter in the URL
ModificadaAlta (7.1)0.54%—Ip2location Country Blocker7/2/202217/6/2026
The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from…
ModificadaMedia (5.5)0.44%—Gglocker Project Gglocker16/12/202117/6/2026
GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.
ModificadaMedia (4.6)0.32%—Oneplus APP Locker9/10/202017/6/2026
OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.
ModificadaAlta (7.8)0.63%—Iobit Unlocker23/6/202017/6/2026
The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to delete, move, or copy arbitrary files via IOCTL code 0x222124.
ModificadaAlta (7.1)0.91%💥 PoCIobit Unlocker23/6/202017/6/2026
The driver in IOBit Unlocker 1.1.2 allows a low-privileged user to unlock a file and kill processes (even ones running as SYSTEM) that hold a handle, via IOCTL code 0x222124.
ModificadaMedia (5.4)0.68%—Byonepress Social Locker26/9/201917/6/2026
The social-locker plugin before 4.2.5 for WordPress has CSRF with resultant XSS via the wp-admin/edit.php?post_type=opanda-item&page=license-manager-sociallocker-next licensekey parameter.
ModificadaMedia (6.1)0.86%—Ht2labs Learning Locker16/7/201917/6/2026
In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.
ModificadaMedia (5.3)0.68%—O.bike Smart Locker FirmwareO.bike Obike-stationless Bike Sharing14/9/201817/6/2026
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.
ModificadaAlta (7.5)1.2%—Photo,video Locker-calculator Project Photo,video Locker-calculator20/2/201817/6/2026
smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN.
ModificadaAlta (7.5)0.64%—Photo,video Locker-calculator Project Photo,video Locker-calculator20/2/201817/6/2026
The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.
ModificadaMedia (6.8)0.44%—KDE KscreenlockerKDE Plasma-workspaceFedoraproject FedoraOpensuse Leap23/12/201617/6/2026
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
ModificadaMedia (5.4)0.27%—RIX GO Locker Theme Project RIX GO Locker Theme9/9/201417/6/2026
The Rix GO Locker Theme (aka com.jiubang.goscreenlock.theme.rix.getjar) application 1.20.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4)1.4%—Xythos Digital LockerXythos Enterprise Document ManagerXythos Webfile Server27/6/200716/6/2026
Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.
Orbitaley — Vulnerabilidades