Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.42%—Ethereum Blockchain11/9/202317/6/2026
Un problema en Ethereum Blockchain v0.1.1+commit.6ff4cd6 hace que el saldo se ponga a cero cuando el valor de betsize+casino.balance excede el umbral.
ModificadaAlta (7.8)0.18%—Samsung Blockchain Keystore6/9/202317/6/2026
La falla del mecanismo de protección en bc_tui trustlet de Samsung Blockchain Keystore anterior a la version 1.3.13.5 permite a un atacante local ejecutar código arbitrario.
ModificadaMedia (5.4)0.47%—Sureshchand CHP ADS Block Detector31/8/202317/6/2026
El plugin CHP Ads Block Detector para WordPress es vulnerable a cross-site scripting almacenado a través de la configuración de administrador accesible mediante una acción AJAX en versiones hasta la 3.9.4, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes. Esto permite a atacantes…
ModificadaMedia (4.3)0.52%—Sureshchand CHP ADS Block Detector31/8/202317/6/2026
El plugin CHP Ads Block Detector para WordPress es vulnerable a la actualización y el restablecimiento no autorizados de la configuración del plugin debido a una comprobación de capacidad faltante en la función chp_abd_action en versiones hasta la 3.9.4, inclusive. Esto hace posible que atacantes con nivel de…
ModificadaMedia (4.3)0.30%—Sureshchand CHP ADS Block Detector31/8/202317/6/2026
El plugin CHP Ads Block Detector para WordPress es vulnerable a la falsificación de petición en sitios cruzados en versiones hasta la 3.9.4, inclusive. Esto se debe a la validación de nonce faltante o incorrecta en la función chp_abd_action. Esto hace posible que atacantes no autenticados actualicen o restablezcan la…
ModificadaMedia (4.8)0.44%—Didcode Spamreferrerblock30/8/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en el plugin SpamReferrerBlock de Didier Sampaolo que afecta a las versiones 2.22 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de administrador o superior.
ModificadaMedia (4.8)0.35%—Supersoju Block Referer Spam23/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Supersoju Block Referer Spam plugin <= 1.1.9.4 versions.
ModificadaMedia (4.8)0.37%—Stopbadbots Block BAD Bots AND Stop BAD Bots Crawlers AND Spiders AND Anti Spam Protection23/8/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Bill Minozzi Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin <= 7.31 versions.
ModificadaBaja (2.4)0.14%—Sulimet 5-in-1 Smart Door Lock Firmware15/8/202317/6/2026
Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
ModificadaMedia (4.6)0.14%—Etekcity 3-in-1 Smart Door Lock Firmware15/8/202317/6/2026
Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
ModificadaAlta (7.3)0.17%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)1.2%💥 PoCSherlock GYM Management System9/8/202317/6/2026
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username and password fields, enabling SQL…
ModificadaCrítica (9.8)1.3%—Hgiga Isherlock21/7/202317/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Injection.This issue affects iSherlock 4.5: before iSherlock-user-4.5-174; iSherlock 5.5: before…
ModificadaCrítica (9.8)1.0%—Locke-bot Project Locke-bot18/7/202317/6/2026
SQL injection vulnerability in HKing2802 Locke-Bot 2.0.2 allows remote attackers to run arbitrary SQL commands via crafted string to /src/db.js, /commands/mute.js, /modules/event/messageDelete.js.
ModificadaCrítica (9.8)0.50%—Nesote Inout Blockchain Easypayments15/7/202317/6/2026
A vulnerability, which was classified as critical, was found in Nesote Inout Blockchain EasyPayments 1.0. Affected is an unknown function of the file /index.php/payment/getcoinaddress of the component POST Parameter Handler. The manipulation of the argument coinid leads to sql injection. It is possible to launch the…
ModificadaCrítica (9.8)0.50%—Nesote Inout Blockchain Fiatexchanger11/7/202317/6/2026
A vulnerability classified as critical has been found in Nesote Inout Blockchain FiatExchanger 3.0. This affects an unknown part of the file /index.php/coins/update_marketboxslider of the component POST Parameter Handler. The manipulation of the argument marketcurrency leads to sql injection. It is possible to…
ModificadaMedia (6.5)0.22%—Areoi ALL Bootstrap Blocks11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in AREOI All Bootstrap Blocks plugin <= 1.3.6 versions.
ModificadaAlta (8.8)0.31%—Lionscripts IP Blocker Lite10/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in LionScripts.Com LionScripts: IP Blocker Lite plugin <= 11.1.1 versions.
ModificadaMedia (6.5)0.26%—Wafucn Wafu Keyless Smart Lock Firmware22/6/202317/6/2026
An issue was discovered in WAFU Keyless Smart Lock v1.0 allows attackers to unlock a device via code replay attack.
ModificadaCrítica (9.8)1.3%—Tmtmakine Lockcell Firmware13/6/202317/6/2026
Reliance on Cookies without Validation and Integrity Checking in a Security Decision vulnerability in TMT Lockcell allows Privilege Abuse, Authentication Bypass. This issue affects Lockcell: before 15.
ModificadaCrítica (9.8)3.7%—Tmtmakine Lockcell Firmware13/6/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in TMT Lockcell allows Command Injection. This issue affects Lockcell: before 15.
ModificadaCrítica (9.8)1.3%—Tmtmakine Lockcell Firmware13/6/202317/6/2026
Authorization Bypass Through User-Controlled Key vulnerability in TMT Lockcell allows Authentication Abuse, Authentication Bypass. This issue affects Lockcell: before 15.
ModificadaCrítica (9.8)1.7%💥 PoCTmtmakine Lockcell Firmware13/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TMT Lockcell allows SQL Injection. This issue affects Lockcell: before 15.
ModificadaMedia (4.3)0.32%—Wpdeveloper Essential Blocks9/6/202317/6/2026
The Essential Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.6. This is due to missing or incorrect nonce validation on the save function. This makes it possible for unauthenticated attackers to change plugin settings via a forged request granted they can…