Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.42% | — | Ethereum Blockchain | 11/9/2023 | 17/6/2026 | Un problema en Ethereum Blockchain v0.1.1+commit.6ff4cd6 hace que el saldo se ponga a cero cuando el valor de betsize+casino.balance excede el umbral. | |
| Modificada | Alta (7.8) | 0.18% | — | Samsung Blockchain Keystore | 6/9/2023 | 17/6/2026 | La falla del mecanismo de protección en bc_tui trustlet de Samsung Blockchain Keystore anterior a la version 1.3.13.5 permite a un atacante local ejecutar código arbitrario. | |
| Modificada | Media (5.4) | 0.47% | — | Sureshchand CHP ADS Block Detector | 31/8/2023 | 17/6/2026 | El plugin CHP Ads Block Detector para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración de administrador accesible mediante una acción AJAX en versiones hasta la 3.9.4, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes… | |
| Modificada | Media (4.3) | 0.52% | — | Sureshchand CHP ADS Block Detector | 31/8/2023 | 17/6/2026 | El plugin CHP Ads Block Detector para WordPress es vulnerable a la actualización y el restablecimiento no autorizados de la configuración del plugin debido a una comprobación de capacidad faltante en la función chp_abd_action en versiones hasta la 3.9.4, inclusive. Esto hace posible que atacantes con nivel de… | |
| Modificada | Media (4.3) | 0.30% | — | Sureshchand CHP ADS Block Detector | 31/8/2023 | 17/6/2026 | El plugin CHP Ads Block Detector para WordPress es vulnerable a la falsificación de petición en sitios cruzados en versiones hasta la 3.9.4, inclusive. Esto se debe a la validación de nonce faltante o incorrecta en la función chp_abd_action. Esto hace posible que atacantes no autenticados actualicen o restablezcan la… | |
| Modificada | Media (4.8) | 0.44% | — | Didcode Spamreferrerblock | 30/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en el plugin SpamReferrerBlock de Didier Sampaolo que afecta a las versiones 2.22 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de administrador o superior. | |
| Modificada | Media (4.8) | 0.35% | — | Supersoju Block Referer Spam | 23/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Supersoju Block Referer Spam plugin <= 1.1.9.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Stopbadbots Block BAD Bots AND Stop BAD Bots Crawlers AND Spiders AND Anti Spam Protection | 23/8/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bill Minozzi Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin <= 7.31 versions. | |
| Modificada | Baja (2.4) | 0.14% | — | Sulimet 5-in-1 Smart Door Lock Firmware | 15/8/2023 | 17/6/2026 | Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device. | |
| Modificada | Media (4.6) | 0.14% | — | Etekcity 3-in-1 Smart Door Lock Firmware | 15/8/2023 | 17/6/2026 | Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.2% | 💥 PoC | Sherlock GYM Management System | 9/8/2023 | 17/6/2026 | Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL… | |
| Modificada | Crítica (9.8) | 1.3% | — | Hgiga Isherlock | 21/7/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before… | |
| Modificada | Crítica (9.8) | 1.0% | — | Locke-bot Project Locke-bot | 18/7/2023 | 17/6/2026 | SQL injection vulnerability in HKing2802 Locke-Bot 2.0.2 allows remote attackers to run arbitrary SQL commands via crafted string to /src/db.js, /commands/mute.js, /modules/event/messageDelete.js. | |
| Modificada | Crítica (9.8) | 0.50% | — | Nesote Inout Blockchain Easypayments | 15/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Nesote Inout Blockchain EasyPayments 1.0. Affected is an unknown function of the file /index.php/payment/getcoinaddress of the component POST Parameter Handler. The manipulation of the argument coinid leads to sql injection. It is possible to launch the… | |
| Modificada | Crítica (9.8) | 0.50% | — | Nesote Inout Blockchain Fiatexchanger | 11/7/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Nesote Inout Blockchain FiatExchanger 3.0. This affects an unknown part of the file /index.php/coins/update_marketboxslider of the component POST Parameter Handler. The manipulation of the argument marketcurrency leads to sql injection. It is possible to… | |
| Modificada | Media (6.5) | 0.22% | — | Areoi ALL Bootstrap Blocks | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <= 1.3.6 versions. | |
| Modificada | Alta (8.8) | 0.31% | — | Lionscripts IP Blocker Lite | 10/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions. | |
| Modificada | Media (6.5) | 0.26% | — | Wafucn Wafu Keyless Smart Lock Firmware | 22/6/2023 | 17/6/2026 | An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack. | |
| Modificada | Crítica (9.8) | 1.3% | — | Tmtmakine Lockcell Firmware | 13/6/2023 | 17/6/2026 | Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15. | |
| Modificada | Crítica (9.8) | 3.7% | — | Tmtmakine Lockcell Firmware | 13/6/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15. | |
| Modificada | Crítica (9.8) | 1.3% | — | Tmtmakine Lockcell Firmware | 13/6/2023 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15. | |
| Modificada | Crítica (9.8) | 1.7% | 💥 PoC | Tmtmakine Lockcell Firmware | 13/6/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection. This issue affects Lockcell: before 15. | |
| Modificada | Media (4.3) | 0.32% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can… |