Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

1033 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
AplazadaCrítica (9.9)0.79%—Blocksy Companion PROAI17/6/202617/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
AplazadaCrítica (9.3)0.40%—Blocksy Companion PROAI17/6/202617/6/2026
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
AplazadaAlta (7.5)0.32%—Crocoblock JetengineAI17/6/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202628/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.
AplazadaMedia (4.3)0.21%—Static BlockAI16/6/202617/6/2026
The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the…
AplazadaAlta (8.8)0.42%—B BlocksAI15/6/202617/6/2026
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
AplazadaAlta (8.8)1.6%—Creativethemes BlocksyAI9/6/202623/7/2026
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which…
AplazadaBaja (3.5)0.24%—Custom Block BuilderAI9/6/202623/7/2026
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary…
AplazadaMedia (6.4)0.35%—Recipe Card Blocks LiteAI8/6/202623/7/2026
The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into…
AplazadaAlta (7.2)0.26%—Wpdeveloper Essential BlocksAI5/6/202623/7/2026
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and…
AplazadaMedia (6.5)0.41%—Meta Field BlockAI28/5/202617/6/2026
The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user has permission to…
AplazadaAlta (7.1)0.25%—Inilerm Advanced IP BlockerAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7.
AplazadaMedia (6.5)0.37%—GenerateblocksAI27/5/202617/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0.
AplazadaMedia (6.4)0.33%—Splide Carousel BlockAI27/5/202623/7/2026
The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI25/5/202624/7/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1.
AplazadaMedia (6.1)0.34%—WP BlockadeAI22/5/202623/7/2026
The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input sanitization and output escaping in the render_shortcode_preview() function. The function receives user input from…
AplazadaMedia (4.3)0.40%—Nimiq-blockchainAI20/5/202623/7/2026
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores them in a peer contact book, eventually leading to address book crash. A PeerContact can legally contain an empty…
AplazadaAlta (7.5)0.76%—Nimiq-blockchainAI20/5/202623/7/2026
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, KeyPair> with a signature…
AplazadaMedia (5.4)0.41%—Nexa BlocksAI20/5/202624/7/2026
The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it…
Orbitaley — Vulnerabilidades