Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

1493 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.8)0.37%—Semalt Blocker Project Semalt Blocker10/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alex Moss Semalt Blocker plugin <= 1.1.3 versions.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaMedia (5.5)0.17%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
ModificadaAlta (7.8)0.19%—Samsung Blockchain Keystore4/5/202317/6/2026
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
ModificadaMedia (5.4)0.36%—Wpdownloadmanager Gutenberg Blocks FOR Wordpress Download Manager3/5/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress Download Manager Gutenberg Blocks by WordPress Download Manager plugin <= 2.1.8 versions.
ModificadaMedia (4.3)0.55%—Creativethemes Blocksy Companion2/5/202317/6/2026
The Blocksy Companion WordPress plugin before 1.8.82 does not ensure that posts to be accessed via a shortcode are already public and can be viewed, allowing any authenticated users, such as subscriber to access draft posts for example
ModificadaAlta (8.8)0.40%—Lenovo Smart Clock Essential With Alexa Built IN Firmware1/5/202317/6/2026
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.
ModificadaAlta (7.5)0.31%—42gears Surelock27/4/202317/6/2026
Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.0.
ModificadaAlta (7.8)0.19%—42gears Surelock27/4/202317/6/2026
Unquoted service Path or Element vulnerability in 42Gears Surelock Windows SureLock Service (NixService.Exe) on Windows application will allows to insert arbitrary code into the service. This issue affects Surelock Windows : from 2.3.12 through 2.40.0.
ModificadaMedia (4.8)0.39%—Codebangers ALL IN ONE Time Clock Lite23/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Codebangers All in One Time Clock Lite plugin <= 1.3.320 versions.
ModificadaMedia (6.5)0.29%—Epiph Form Block20/4/202317/6/2026
Form block is a wordpress plugin designed to make form creation easier. Versions prior to 1.0.2 are subject to a Cross-Site Request Forgery due to a missing nonce check. There is potential for a Cross Site Request Forgery for all form blocks, since it allows to send requests to the forms from any website without a…
ModificadaAlta (7.1)0.74%—Dualspace Lock Master14/4/202317/6/2026
An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the com.ludashi.superlock.util.pref.SharedPrefProviderEntryMethod: insert of the android.net.Uri.insert method.
ModificadaAlta (8.8)1.5%—Crocoblock Jetengine FOR Elementor10/4/202317/6/2026
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
ModificadaCrítica (9.1)1.0%—Phpgurukul Bank Locker Management System9/4/202317/6/2026
A vulnerability classified as critical has been found in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file recovery.php of the component Password Reset. The manipulation of the argument uname/mobile leads to sql injection. It is possible to launch the attack remotely. The…
ModificadaCrítica (9.8)0.73%—Phpgurukul Bank Locker Management System9/4/202317/6/2026
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file index.php of the component Search. The manipulation of the argument searchinput leads to sql injection. The attack may be initiated remotely. The exploit has…
ModificadaMedia (5.4)0.34%—Creativethemes Blocksy Companion6/4/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.
ModificadaMedia (4.3)0.28%—Hasthemes Contact Form 7 Widget FOR Elementor Page Builder & Gutenberg Blocks27/3/202317/6/2026
The Contact Form 7 Widget For Elementor Page Builder & Gutenberg Blocks WordPress plugin before 1.1.6 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
ModificadaAlta (8.1)0.73%—Simplygallery Simply Gallery Blocks With Lightbox27/3/202317/6/2026
The Gallery Blocks with Lightbox WordPress plugin before 3.0.8 has an AJAX endpoint that can be accessed by any authenticated users, such as subscriber. The callback function allows numerous actions, the most serious one being reading and updating the WordPress options which could be used to enable registration with a…
ModificadaMedia (5.3)0.60%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
ModificadaAlta (7.2)0.93%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
ModificadaAlta (7.2)0.93%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
Orbitaley — Vulnerabilidades