Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1033 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Crocoblock JetengineAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine jet-engine allows Reflected XSS.This issue affects JetEngine: from n/a through <= 3.8.0. | |
| Aplazada | Media (6.5) | 0.22% | — | Posimyth Nexter BlocksAI | 20/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Stored XSS.This issue affects Nexter Blocks: from n/a through <= 3.3.3. | |
| Aplazada | Media (6.5) | 0.23% | — | Godaddy CoblocksAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoDaddy CoBlocks coblocks allows Stored XSS.This issue affects CoBlocks: from n/a through <= 3.1.16. | |
| Aplazada | Media (6.1) | 0.27% | — | Xmlrpc Attacks BlockerAI | 19/2/2026 | 17/6/2026 | The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This… | |
| Aplazada | Media (6.4) | 0.24% | — | Advance Block ExtendAI | 19/2/2026 | 17/6/2026 | The Advance Block Extend plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TitleColor block attribute in the Latest Posts Gutenberg block in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (4.3) | 0.18% | — | Country Blocker FOR AdsenseAI | 19/2/2026 | 17/6/2026 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the CBFA_guardar_cbfa() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Aplazada | Media (5.4) | 0.30% | — | BSV Blockchain Typescript SDKAI | 18/2/2026 | 17/6/2026 | The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's BRC-104 authentication implementation caused incorrect signature data preparation, resulting in signature incompatibility between SDK… | |
| Aplazada | Media (4.3) | 0.39% | — | Kadence Blocks AIAI | 18/2/2026 | 17/6/2026 | The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.6.1. This is due to a missing capability check in the `process_image_data_ajax_callback()` function which handles the `kadence_import_process_image_data` AJAX action. The… | |
| Aplazada | Media (4.3) | 0.30% | — | Kadencewp Gutenberg Blocks With AIAI | 18/2/2026 | 17/6/2026 | The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.6.1. This is due to insufficient validation of the `endpoint` parameter in the `get_items()` function of the GetResponse REST API handler. The endpoint's permission check… | |
| Aplazada | Media (4.3) | 0.34% | — | Kadence BlocksAI | 17/2/2026 | 17/6/2026 | The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.5.32. This makes it possible for authenticated attackers, with Contributor-level access and above, to perform… | |
| Aplazada | Alta (7.5) | 0.59% | — | TON BlockchainAITON Virtual MachineAI | 13/2/2026 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the TON Virtual Machine (TVM) within the TON Blockchain before v2025.06. The issue is located in the execution logic of the INMSGPARAM instruction, where the program fails to validate if a specific pointer is null before accessing it. By sending a malicious… | |
| Aplazada | Alta (8.8) | 8.9% | 💥 PoC | Thedevoice Lazy BlocksAI | 11/2/2026 | 17/6/2026 | The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the… | |
| Aplazada | Media (4.4) | 0.28% | — | Wplyr Media BlockAI | 11/2/2026 | 17/6/2026 | The WPlyr Media Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_wplyr_accent_color' parameter in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.26% | — | Theeventscalendar Shortcode AND BlockAI | 10/2/2026 | 17/6/2026 | The The Events Calendar Shortcode & Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ecs-list-events` shortcode `message` attribute in all versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (5.3) | 0.39% | — | Advanced Country BlockerAI | 7/2/2026 | 17/6/2026 | The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and including, 2.3.1 due to the use of a predictable default value for the secret bypass key created during installation without requiring users to change it. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.3) | 0.21% | — | Timeline BlockAI | 6/2/2026 | 17/6/2026 | The Timeline Block – Beautiful Timeline Builder for WordPress (Vertical & Horizontal Timelines) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.3 via the tlgb_shortcode() function due to missing validation on a user controlled key. This makes it possible… | |
| Aplazada | Media (6.7) | 0.24% | — | Codeblocks Code BlocksAI | 5/2/2026 | 6/8/2026 | — | |
| Aplazada | Alta (7.2) | 0.33% | — | ALL IN ONE Image Viewer BlockAI | 5/2/2026 | 17/6/2026 | The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Media (6.5) | 0.19% | — | Crocoblock JET Elements FOR ElementorAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows DOM-Based XSS.This issue affects JetElements For Elementor: from n/a through <= 2.7.12.2. | |
| Aplazada | Media (5.3) | 0.40% | — | Spectra Gutenberg BlocksAI | 3/2/2026 | 17/6/2026 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.19.17. This is due to the plugin failing to check `post_password_required()` before rendering post excerpts in the `render_excerpt()` function and the… | |
| Aplazada | Alta (8.4) | 0.21% | — | Codeblocks Code BlocksAI | 30/1/2026 | 17/6/2026 | Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially… | |
| Aplazada | Media (4.6) | 0.42% | — | Codeblocks Code BlocksAI | 30/1/2026 | 17/6/2026 | Code Blocks 20.03 contains a denial of service vulnerability that allows attackers to crash the application by manipulating input in the FSymbols search field. Attackers can paste a large payload of 5000 repeated characters into the search field to trigger an application crash. | |
| Aplazada | Media (6.4) | 0.21% | — | BlockartAI | 28/1/2026 | 17/6/2026 | The BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the BlockArt Counter in all versions up to, and including, 2.2.14 due to insufficient input sanitization and output escaping on user… | |
| Aplazada | Media (6.8) | 0.34% | — | Recipe Card Blocks LiteAI | 26/1/2026 | 17/6/2026 | The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a SQL statement, allowing contributors and above to perform SQL injection attacks. | |
| Aplazada | Alta (7.2) | 0.36% | — | Frontis BlocksAI | 24/1/2026 | 17/6/2026 | The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.1.6. This is due to insufficient restriction on the 'url' parameter in the 'template_proxy' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… |