Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
1489 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.15% | — | Acronis Devicelock DLPAI | 3/6/2026 | 22/7/2026 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. | |
| Aplazada | Media (6.5) | 0.41% | — | Meta Field BlockAI | 28/5/2026 | 17/6/2026 | The Meta Field Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.5.1. This is due to the plugin allowing users to specify arbitrary object IDs and object types via block attributes without validating whether the authenticated user has permission to… | |
| Aplazada | Crítica (9.3) | 1.3% | 💥 PoC | Github ActionsAISherlockAI | 27/5/2026 | 17/6/2026 | Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pull_request_target trigger. Any GitHub user can execute arbitrary commands on the CI runner and exfiltrate the… | |
| Aplazada | Media (5.5) | 0.14% | — | Spsoftmobile ApplockAI | 27/5/2026 | 5/10/2026 | SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mechanisms, the lock is implemented with a custom overlay that fails to consistently enforce authentication. By navigating… | |
| Aplazada | Alta (7.1) | 0.25% | — | Inilerm Advanced IP BlockerAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7. | |
| Aplazada | Media (6.5) | 0.37% | — | GenerateblocksAI | 27/5/2026 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Tom GenerateBlocks allows Retrieve Embedded Sensitive Data. This issue affects GenerateBlocks: from n/a through 2.1.0. | |
| Aplazada | Media (6.4) | 0.33% | — | Splide Carousel BlockAI | 27/5/2026 | 23/7/2026 | The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Baja (2.4) | 0.19% | — | Applock ZAIGoogle AndroidAI | 26/5/2026 | 23/7/2026 | AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure… | |
| Aplazada | Baja (2.4) | 0.19% | — | Spsoftmobile ApplockAI | 26/5/2026 | 24/7/2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation through exposed routes… | |
| Aplazada | Baja (2.4) | 0.18% | — | Creative Core APP LockAI | 26/5/2026 | 24/7/2026 | Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's secure authentication APIs. By navigating cascading interface flows - insecure navigation… | |
| Aplazada | Media (5.2) | 0.18% | — | Spsoftmobile ApplockAI | 26/5/2026 | 24/7/2026 | SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URIs. This unsafe navigation path results in script execution and may allow UI spoofing or privilege escalation. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1. | |
| Aplazada | Media (6.1) | 0.34% | — | WP BlockadeAI | 22/5/2026 | 23/7/2026 | The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode' parameter in all versions up to and including 0.9.14. This is due to insufficient input sanitization and output escaping in the render_shortcode_preview() function. The function receives user input from… | |
| Aplazada | Media (4.3) | 0.40% | — | Nimiq-blockchainAI | 20/5/2026 | 23/7/2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and stores them in a peer contact book, eventually leading to address book crash. A PeerContact can legally contain an empty… | |
| Aplazada | Alta (7.5) | 0.76% | — | Nimiq-blockchainAI | 20/5/2026 | 23/7/2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, KeyPair> with a signature… | |
| Aplazada | Media (5.4) | 0.41% | — | Nexa BlocksAI | 20/5/2026 | 24/7/2026 | The Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in versions up to and including 1.1.1. This is due to the import_demo() function accepting a user-supplied URL in the demo_json_file POST parameter and passing it… | |
| Aplazada | Media (5.1) | 0.21% | — | PHP TimeclockAI | 15/5/2026 | 17/6/2026 | PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers can append malicious payloads to login.php, timeclock.php, audit.php, and timerpt.php endpoints, or inject code through… | |
| Aplazada | Alta (8.8) | 0.27% | — | PHP TimeclockAI | 15/5/2026 | 17/6/2026 | PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database contents. Attackers can submit crafted POST requests with SQL payloads using SLEEP functions or RLIKE conditional statements… | |
| Aplazada | Media (6.4) | 0.26% | — | Meta Field BlockAI | 14/5/2026 | 17/6/2026 | The Meta Field Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tagName' block attribute in all versions up to, and including, 1.5.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,… | |
| Pendiente de análisis | Alta (8.6) | 0.15% | — | Atomic Alarm ClockAI | 13/5/2026 | 17/6/2026 | Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to… | |
| Aplazada | Media (6.4) | 0.33% | — | Snow Monkey BlocksAI | 13/5/2026 | 17/6/2026 | The Snow Monkey Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-slick' attribute in all versions up to, and including, 24.1.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (6.4) | 0.32% | — | Scratchblocks FOR WPAI | 12/5/2026 | 17/6/2026 | The scratchblocks for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' attribute of the 'scratchblocks' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.1) | 0.19% | — | Ip2location Country BlockerAI | 10/5/2026 | 24/7/2026 | WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when… | |
| Analizada | Media (5.3) | 0.30% | — | Hitachi VSP E1090h FirmwareHitachi VSP E790h FirmwareHitachi VSP E590h FirmwareHitachi VSP E390h Firmware+16 | 7/5/2026 | 17/6/2026 | Improper restriction of excessive authentication attempts vulnerability in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One Block 23, One Block… | |
| Analizada | Crítica (9.8) | 0.55% | — | Hitachi Virtual Storage ONE BlockHitachi VSP G130 FirmwareHitachi VSP G150 FirmwareHitachi VSP G350 Firmware+16 | 7/5/2026 | 17/6/2026 | Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H, Hitachi Virtual Storage Platform One… |