Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.32%—Kadence BlocksAI18/6/202618/6/2026
The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.7.5 via the editor_assets_variables. This makes it possible for authenticated attackers, with contributor-level access and above, to extract the…
AplazadaCrítica (9.3)0.40%—WP Travel Gutenberg BlocksAI17/6/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.
AplazadaMedia (6.8)0.28%—Crocoblock JetformbuilderAI17/6/202616/9/2026
Incorrect Privilege Assignment vulnerability in Jetmonsters JetFormBuilder allows Privilege Escalation. This issue affects JetFormBuilder: from n/a through 3.6.1.
AplazadaAlta (7.1)0.25%—Crocoblock JetformbuilderAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
AplazadaCrítica (9.8)0.56%—Crocoblock JetengineAI17/6/202617/6/2026
Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.
AplazadaAlta (7.1)0.25%—Crocoblock JetengineAI17/6/202617/6/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions.
AplazadaCrítica (9.9)0.79%—Blocksy Companion PROAI17/6/202617/6/2026
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
AplazadaCrítica (9.3)0.40%—Blocksy Companion PROAI17/6/202617/6/2026
Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.
AplazadaAlta (7.5)0.32%—Crocoblock JetengineAI17/6/202617/6/2026
The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row…
AplazadaCrítica (9.3)0.40%—Crocoblock JetengineAI17/6/202628/9/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1.
AplazadaMedia (4.3)0.21%—Static BlockAI16/6/202617/6/2026
The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2. This is due to the static_block_content() shortcode handler retrieving a post via get_post() using an attacker-supplied 'id' attribute and outputting its post_content without verifying the…
AplazadaAlta (8.8)0.42%—B BlocksAI15/6/202617/6/2026
Contributor Privilege Escalation in B Blocks <= 2.0.31 versions.
AplazadaBaja (3.5)0.24%—Ays-pro Secure Copy Content Protection AND Content LockingAI12/6/202617/6/2026
The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AplazadaAlta (8.8)1.6%—Creativethemes BlocksyAI9/6/202623/7/2026
The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_meta' REST API field and the V200 database migration in versions up to and including 2.1.35. This is due to insufficient input sanitization in the blocksy_sanitize_post_meta_options() function, which…
AplazadaBaja (3.5)0.24%—Custom Block BuilderAI9/6/202623/7/2026
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrators on multisite installations (or single-site installs with DISALLOW_UNFILTERED_HTML defined) to inject arbitrary…
AplazadaMedia (6.4)0.35%—Recipe Card Blocks LiteAI8/6/202623/7/2026
The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions up to, and including, 3.4.13. This is due to the 'WPZOOM_Helpers::deserialize_block_attributes' method converting unicode-encoded sequences back into…
AplazadaAlta (7.2)0.26%—Wpdeveloper Essential BlocksAI5/6/202623/7/2026
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and…
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
AplazadaAlta (7.3)0.15%—Acronis Devicelock DLPAI3/6/202622/7/2026
Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.
Orbitaley — Vulnerabilidades