Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1493 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.57% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the template_count function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is… | |
| Modificada | Media (4.3) | 0.61% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the templates function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin template information. While a nonce check is present,… | |
| Modificada | Media (4.3) | 0.51% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the get function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to obtain plugin settings. While a nonce check is present, it is only… | |
| Modificada | Media (4.3) | 0.57% | — | Wpdeveloper Essential Blocks | 9/6/2023 | 17/6/2026 | The Essential Blocks plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on the save function in versions up to, and including, 4.0.6. This makes it possible for subscriber-level attackers to save plugin settings. While a nonce check is present, it is only executed… | |
| Modificada | Media (4.3) | 0.50% | — | Vektor-inc VK Blocks | 3/6/2023 | 17/6/2026 | The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change the 'vk_font_awesome_version' option to an arbitrary value. | |
| Modificada | Media (4.3) | 0.54% | — | Vektor-inc VK Blocks | 3/6/2023 | 17/6/2026 | The VK Blocks plugin for WordPress is vulnerable to improper authorization via the REST 'update_vk_blocks_options' function in versions up to, and including, 1.57.0.5. This allows authenticated attackers, with contributor-level permissions or above, to change plugin settings including default icons. | |
| Modificada | Alta (8.8) | 0.73% | — | Sguda U-lock Firmware | 2/6/2023 | 17/6/2026 | SGUDA U-Lock central lock control service’s user management function has incorrect authorization. A remote attacker with general user privilege can exploit this vulnerability to call privileged APIs to access, modify and delete user information. | |
| Modificada | Alta (8.8) | 0.73% | — | Sguda U-lock Firmware | 2/6/2023 | 17/6/2026 | SGUDA U-Lock central lock control service’s lock management function has incorrect authorization. A remote attacker with general privilege can exploit this vulnerability to call privileged APIs to acquire information, manipulate or disrupt the functionality of arbitrary electronic locks. | |
| Modificada | Alta (7.5) | 1.2% | — | Amdroidapp Alarm Clock FOR Heavy Sleepers | 30/5/2023 | 17/6/2026 | An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database. | |
| Modificada | Crítica (9.8) | 1.2% | — | Amdroidapp Alarm Clock FOR Heavy Sleepers | 30/5/2023 | 17/6/2026 | An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component. | |
| Modificada | Crítica (9.8) | 0.58% | — | Applika Call Blocker | 30/5/2023 | 17/6/2026 | The Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of privilege attack. | |
| Modificada | Crítica (9.8) | 1.2% | — | Applika Call Blocker | 30/5/2023 | 17/6/2026 | The Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its database that is related to user privacy settings and affects the implementation of the normal functionality of the application. An attacker can use this to cause an escalation of… | |
| Modificada | Alta (7.5) | 1.2% | — | Applika Call Blocker | 30/5/2023 | 17/6/2026 | The Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty data into the application's database. When the application starts, it loads the data from the database into memory. Once the attacker injects too much data, the application… | |
| Modificada | Alta (7.8) | 0.34% | — | Dualspace Lock Master | 30/5/2023 | 17/6/2026 | The Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data that affects many app functions. Malicious modifications by unauthorized apps can cause security issues, such as functionality manipulation, resulting in a severe escalation of… | |
| Modificada | Alta (8.8) | 0.26% | — | Crocoblock Jetformbuilder | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Admin Block Country Project Admin Block Country | 26/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in TheOnlineHero - Tom Skroza Admin Block Country plugin <= 7.1.4 versions. | |
| Modificada | Media (5.5) | 0.23% | — | Simpledesign Diary With Lock\ | 24/5/2023 | 17/6/2026 | A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the… | |
| Modificada | Alta (8.8) | 0.26% | — | Dogblocker Minify Html | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Minify HTML plugin <= 2.1.7 vulnerability. | |
| Modificada | Alta (8.8) | 0.26% | — | Dogblocker Read More Excerpt Link | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tim Eckel Read More Excerpt Link plugin <= 1.6 versions. | |
| Modificada | Media (5.4) | 0.61% | — | Vektor-inc VK Blocks | 23/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Post function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.61% | — | Vektor-inc VK Blocks | 23/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Tag edit function of VK Blocks 1.53.0.1 and earlier and VK Blocks Pro 1.53.0.1 and earlier allows a remote authenticated attacker to inject an arbitrary script. | |
| Modificada | Crítica (9.8) | 0.76% | — | Posthemes Posstaticblocks | 16/5/2023 | 17/6/2026 | Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook(). | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack | |
| Modificada | Media (4.3) | 0.28% | — | Infigosoftware Clock IN Portal- Staff & Attendance Management | 15/5/2023 | 17/6/2026 | The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack |