Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Crítica (9.9) | 0.79% | — | Blocksy Companion PROAI | 17/6/2026 | 17/6/2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Blocksy Companion PROAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1. | |
| Aplazada | Media (4.3) | 0.21% | — | Static BlockAI | 16/6/2026 | 17/6/2026 | The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the… | |
| Aplazada | Alta (8.8) | 0.42% | — | B BlocksAI | 15/6/2026 | 17/6/2026 | Contributor Privilege Escalation in B Blocks <= 2.0.31 versions. | |
| Aplazada | Alta (8.8) | 1.6% | — | Creativethemes BlocksyAI | 9/6/2026 | 23/7/2026 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which… | |
| Aplazada | Baja (3.5) | 0.24% | — | Custom Block BuilderAI | 9/6/2026 | 23/7/2026 | The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary… | |
| Aplazada | Media (6.4) | 0.35% | — | Recipe Card Blocks LiteAI | 8/6/2026 | 23/7/2026 | The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into… | |
| Aplazada | Alta (7.2) | 0.26% | — | Wpdeveloper Essential BlocksAI | 5/6/2026 | 23/7/2026 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and… | |
| Aplazada | Media (6.5) | 0.41% | — | Meta Field BlockAI | 28/5/2026 | 17/6/2026 | The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user has permission to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Inilerm Advanced IP BlockerAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7. | |
| Aplazada | Media (6.5) | 0.37% | — | GenerateblocksAI | 27/5/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0. | |
| Aplazada | Media (6.4) | 0.33% | — | Splide Carousel BlockAI | 27/5/2026 | 23/7/2026 | The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1. | |
| Aplazada | Media (6.1) | 0.34% | — | WP BlockadeAI | 22/5/2026 | 23/7/2026 | The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input sanitization and output escaping in the render_shortcode_preview() function. The function receives user input from… | |
| Aplazada | Media (4.3) | 0.40% | — | Nimiq-blockchainAI | 20/5/2026 | 23/7/2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores them in a peer contact book, eventually leading to address book crash. A PeerContact can legally contain an empty… | |
| Aplazada | Alta (7.5) | 0.76% | — | Nimiq-blockchainAI | 20/5/2026 | 23/7/2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, KeyPair> with a signature… | |
| Aplazada | Media (5.4) | 0.41% | — | Nexa BlocksAI | 20/5/2026 | 24/7/2026 | The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it… |