Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

1489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)1.8%—DrivelockAI29/7/202630/7/2026
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP…
AplazadaAlta (8.8)0.71%—DrivelockAI29/7/202631/7/2026
DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installations of DriveLock. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 4568 by default. The…
AplazadaMedia (5.3)1.5%—DrivelockAI29/7/202630/7/2026
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP…
AplazadaAlta (7.5)1.8%—DrivelockAI29/7/202630/7/2026
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP…
AplazadaMedia (4.3)0.34%—Survey Form BlockAI29/7/202630/7/2026
The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_all_data() function in all versions up to, and including, 1.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export all survey…
AplazadaMedia (6.9)0.38%—Igloohome Smart Lock Mobile APPAI28/7/202630/7/2026
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
AplazadaMedia (6.4)0.43%—Cozythemes Cozy BlocksAI28/7/202628/7/2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This…
AplazadaMedia (6.5)0.22%—Gallery PhotoblocksAI27/7/202627/7/2026
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
AplazadaMedia (5.4)0.22%—Affiliatexblocks AffiliatexAI27/7/202627/7/2026
Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.
AplazadaMedia (6.4)0.43%—Cozythemes Cozy BlocksAI24/7/202624/7/2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon.view' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes it…
AplazadaMedia (6.4)0.43%—Cozythemes Cozy BlocksAI24/7/202624/7/2026
The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute in all versions up to, and including, 2.2.11 due to insufficient input sanitization and output escaping. This makes…
AplazadaMedia (4.3)0.86%—Posimyth Nexter BlocksAI24/7/202624/7/2026
The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 5.0.0 via the 'plus_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary…
AplazadaMedia (6.4)0.33%—Postx Post Grid Gutenberg BlocksAI24/7/202624/7/2026
The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all versions up to, and including, 5.0.32 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.9)0.19%—Crocoblock JetengineAI23/7/202623/7/2026
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions.
AplazadaMedia (6.5)0.22%—Crocoblock Jetelements FOR ElementorAI23/7/202623/7/2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions.
AplazadaMedia (4.4)0.21%—Photo BlockAI23/7/202623/7/2026
Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.
AplazadaMedia (6.4)0.32%—Spectra Gutenberg BlocksAI20/7/202622/7/2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in all versions up to, and including, 2.19.28 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…
AplazadaMedia (5.3)0.39%—Fense Proxy VPN BlockerAI17/7/202621/7/2026
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*…
AplazadaMedia (5.3)0.33%—Crocoblock JetsearchAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-search allows Retrieve Embedded Sensitive Data.This issue affects JetSearch: from n/a through <= 3.6.1.2.
AplazadaMedia (5.3)0.33%—Crocoblock Jetblocks FOR ElementorAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Retrieve Embedded Sensitive Data.This issue affects JetBlocks For Elementor: from n/a through <= 1.5.0.
AplazadaMedia (5.3)0.33%—Crocoblock JET ReviewsAI13/7/202613/7/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-reviews allows Retrieve Embedded Sensitive Data.This issue affects JetReviews: from n/a through <= 3.0.1.
AplazadaMedia (5.3)0.29%—Presstigers Universal ClocksAI13/7/202613/7/2026
Missing Authorization vulnerability in PressTigers Universal Clocks universal-clocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Universal Clocks: from n/a through <= 1.2.0.
AplazadaAlta (7.1)0.25%—Proxy & VPN BlockerAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.
AplazadaAlta (8.8)0.42%—Tusharimran AblocksAI13/7/202613/7/2026
Incorrect Privilege Assignment vulnerability in Kodezen LLC aBlocks ablocks allows Privilege Escalation.This issue affects aBlocks: from n/a through < 2.9.1.
AplazadaMedia (6.4)0.45%—Simply Gallery BlockAI11/7/202613/7/2026
The SimpLy Gallery Block & Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via block attributes in all versions up to, and including, 3.3.3.2. This is due to insufficient input sanitization and output escaping on the sliderMaxHeight block attribute in the pgc_sgb_render_callback() function.…
Orbitaley — Vulnerabilidades