Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.3)0.27%—Crocoblock Jetelements19/6/202417/6/2026
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
ModificadaCrítica (9.8)0.45%—Crocoblock Jetelements19/6/202417/6/2026
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
ModificadaAlta (7.5)0.40%—Crocoblock Jetelements19/6/202417/6/2026
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
AplazadaAlta (8.8)0.55%—Crocoblock JetengineAI17/5/202417/6/2026
Improper Privilege Management vulnerability in Crocoblock JetEngine allows Privilege Escalation.This issue affects JetEngine: from n/a through 3.2.4.
AplazadaAlta (7.2)0.76%—Crocoblock JetformbuilderAI17/5/202417/6/2026
Improper Privilege Management vulnerability in Crocoblock JetFormBuilder allows Privilege Escalation.This issue affects JetFormBuilder: from n/a through 3.0.8.
AplazadaMedia (6.3)0.21%—Microchip SAM E70AIMicrochip SAM S70AIMicrochip SAM V70AIMicrochip SAM V71AI+816/5/202417/6/2026
A voltage glitch during the startup of EEFC NVM controllers on Microchip SAM E70/S70/V70/V71, SAM G55, SAM 4C/4S/4N/4E, and SAM 3S/3N/3U microcontrollers allows access to the memory bus via the debug interface even if the security bit is set.
AplazadaMedia (5.3)0.37%—Crocoblock JetformbuilderAI24/4/202417/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Crocoblock JetFormBuilder allows Code Injection.This issue affects JetFormBuilder: from n/a through 3.1.4.
AplazadaAlta (8.7)0.55%—Microchip Mpfs2AI18/4/202417/6/2026
The devices allow access to an unprotected endpoint that allows MPFS file system binary image upload without authentication. The MPFS2 file system module provides a light-weight read-only file system that can be stored in external EEPROM, external serial flash, or internal flash program memory. This file system serves…
ModificadaMedia (5.4)0.34%—Crocoblock Jetwidgets FOR Elementor9/4/202417/6/2026
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the widget button URL in all versions up to, and including, 1.0.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.4)0.42%—Crocoblock Jetwidgets FOR Elementor9/4/202417/6/2026
The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Animated Box widget in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and…
ModificadaCrítica (9.8)0.65%—Microchip Maxview Storage Manager9/1/202417/6/2026
A vulnerability has been identified in SIMATIC IPC1047E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC647E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows), SIMATIC IPC847E (All versions with maxView Storage Manager < V4.14.00.26068 on Windows). In default…
ModificadaCrítica (10)0.53%—Microchip Maxview Storage Manager8/1/202417/6/2026
In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched…
ModificadaAlta (8.8)0.72%—Crocoblock Jetelements31/12/202317/6/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.
ModificadaAlta (8.8)0.24%—Crocoblock Jetelements FOR Elementor18/12/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
ModificadaCrítica (9.8)1.0%—Microcks4/12/202317/6/2026
Microcks up to 1.17.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /jobs and /artifact/download. This vulnerability allows attackers to access network resources and sensitive information via a crafted GET request.
ModificadaCrítica (9.1)0.87%—Microchip Mplab Network Creator10/10/202317/6/2026
In Microchip MPLAB Net 3.6.1, TCP ISNs are improperly random.
ModificadaMedia (4.7)0.31%—Schollz Croc20/9/202317/6/2026
An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.
ModificadaAlta (7.8)0.36%—Schollz Croc20/9/202317/6/2026
An issue was discovered in Croc through 9.6.5. A sender may place ANSI or CSI escape sequences in a filename to attack the terminal device of a receiver.
ModificadaAlta (7.8)0.36%—Schollz Croc20/9/202317/6/2026
An issue was discovered in Croc through 9.6.5. A sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized_keys file.
ModificadaMedia (5.3)0.49%—Schollz Croc20/9/202317/6/2026
An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.
ModificadaMedia (5.3)0.77%—Schollz Croc20/9/202317/6/2026
An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.
ModificadaMedia (5.5)0.37%—Schollz Croc20/9/202317/6/2026
An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.
ModificadaMedia (4.4)0.25%—Intel MicrocodeDebian LinuxFedoraproject FedoraIntel Xeon D-2745nx Firmware+13511/8/202317/6/2026
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)3.0%—Redhat Enterprise LinuxXENIntel MicrocodeIntel Xeon E-2314 Firmware+53011/8/202317/6/2026
Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (8.8)0.26%—Crocoblock Jetformbuilder28/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Crocoblock JetFormBuilder — Dynamic Blocks Form Builder plugin <= 3.0.6 versions.
Orbitaley — Vulnerabilidades