Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.57%—Wpdeveloper Essential Blocks9/6/202317/6/2026
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is…
ModificadaMedia (4.3)0.61%—Wpdeveloper Essential Blocks9/6/202317/6/2026
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present,…
ModificadaMedia (4.3)0.51%—Wpdeveloper Essential Blocks9/6/202317/6/2026
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only…
ModificadaMedia (4.3)0.57%—Wpdeveloper Essential Blocks9/6/202317/6/2026
The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed…
ModificadaMedia (4.3)0.50%—Vektor-inc VK Blocks3/6/202317/6/2026
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value.
ModificadaMedia (4.3)0.54%—Vektor-inc VK Blocks3/6/202317/6/2026
The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons.
ModificadaAlta (8.8)0.73%—Sguda U-lock Firmware2/6/202317/6/2026
SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information.
ModificadaAlta (8.8)0.73%—Sguda U-lock Firmware2/6/202317/6/2026
SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploit this vulnerability to call privileged APIs to acquire information, manipulate or disrupt the functionality of arbitrary electronic locks.
ModificadaAlta (7.5)1.2%—Amdroidapp Alarm Clock FOR Heavy Sleepers30/5/202317/6/2026
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database.
ModificadaCrítica (9.8)1.2%—Amdroidapp Alarm Clock FOR Heavy Sleepers30/5/202317/6/2026
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component.
ModificadaCrítica (9.8)0.58%—Applika Call Blocker30/5/202317/6/2026
The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack.
ModificadaCrítica (9.8)1.2%—Applika Call Blocker30/5/202317/6/2026
The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of…
ModificadaAlta (7.5)1.2%—Applika Call Blocker30/5/202317/6/2026
The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker injects too much data, the application…
ModificadaAlta (7.8)0.34%—Dualspace Lock Master30/5/202317/6/2026
The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of…
ModificadaAlta (8.8)0.26%—Crocoblock Jetformbuilder28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.
ModificadaAlta (8.8)0.26%—Admin Block Country Project Admin Block Country26/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in TheOnlineHero - Tom Skroza Admin Block Country plugin <= 7.1.4 versions.
ModificadaMedia (5.5)0.23%—Simpledesign Diary With Lock\24/5/202317/6/2026
A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the…
ModificadaAlta (8.8)0.26%—Dogblocker Minify Html23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability.
ModificadaAlta (8.8)0.26%—Dogblocker Read More Excerpt Link23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Read More Excerpt Link plugin <= 1.6 versions.
ModificadaMedia (5.4)0.61%—Vektor-inc VK Blocks23/5/202317/6/2026
Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
ModificadaMedia (5.4)0.61%—Vektor-inc VK Blocks23/5/202317/6/2026
Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script.
ModificadaCrítica (9.8)0.76%—Posthemes Posstaticblocks16/5/202317/6/2026
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack
ModificadaMedia (4.3)0.28%—Infigosoftware Clock IN Portal- Staff & Attendance Management15/5/202317/6/2026
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack
Orbitaley — Vulnerabilidades