Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

1033 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Video Background BlockAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Video Background Block – Use video as background in the section. <= 2.0.3 versions.
AplazadaMedia (6.5)0.17%—Crocoblock JetelementsAI6/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElements For Elementor jet-elements allows Stored XSS.This issue affects JetElements For Elementor: from n/a through 2.9.2.2.
AplazadaAlta (7.1)0.24%—Epiph Form BlockAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Form Block <= 1.8.1 versions.
AplazadaMedia (6.9)0.27%—Cozythemes Cozy BlocksAI5/10/20266/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in CozyThemes Cozy Blocks cozy-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cozy Blocks: from n/a through 2.2.23.
AplazadaMedia (6.5)0.16%—Bplugins B BlocksAI5/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks b-blocks allows Stored XSS.This issue affects B Blocks: from n/a through 2.1.8.
AplazadaAlta (7.1)0.15%—Kadenceblocks Kadence BlocksAI4/10/20266/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks allows Stored XSS.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through 3.7.11.1.
AplazadaAlta (7.2)0.24%—Crocoblock JetformbuilderAI2/10/20263/10/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
AplazadaBaja (3.1)0.29%—Themeisle Otter BlocksAI2/10/20263/10/2026
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.6 via the 'otter_form_widget_filter' parameter. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaAlta (7.1)0.18%—Parallax Section BlockAI1/10/20261/10/2026
Unauthenticated Cross Site Scripting (XSS) in Parallax Section block <= 2.0.4 versions.
AplazadaMedia (6.4)0.29%—Wpdeveloper Essential BlocksAI1/10/20263/10/2026
The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versions up to, and including, 6.4.5 This is due to insufficient input sanitization and output escaping on marker…
AplazadaAlta (7.1)0.15%—Crocoblock JetformbuilderAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
AplazadaMedia (6.5)0.21%—Creativethemes Blocksy CompanionAI30/9/202630/9/2026
Unauthenticated Broken Access Control in Blocksy Companion <= 2.1.55 versions.
AplazadaMedia (5.5)0.17%—Crocoblock JetengineAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
AplazadaAlta (7.1)0.18%—Crocoblock JetengineAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions.
AplazadaMedia (6.8)0.24%—Audio Player BlockAI30/9/202630/9/2026
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or…
Pendiente de análisisMedia (6.1)0.30%—Netgate PfsenseAIPfblockerngAI25/9/202630/9/2026
Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package
AplazadaMedia (6.1)0.21%—Crocoblock JetformbuilderAI25/9/202625/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for…
AplazadaCrítica (9.3)0.27%—IXO BlockchainAI24/9/202630/9/2026
The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included…
AplazadaMedia (6.5)0.17%—Premium BlocksAI23/9/202623/9/2026
Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.
AplazadaMedia (5.3)0.21%—Post Grid Gutenberg BlocksAI23/9/202623/9/2026
The Post Grid Gutenberg Blocks WordPress plugin before 5.0.41 does not perform an authorization or post-visibility check on a REST API route that returns the custom field keys of a given post, allowing unauthenticated users to disclose the custom field key names of arbitrary posts, including private, draft, pending,…
AplazadaAlta (8.8)0.49%—Openwrt Luci-app-adblock-fastAI21/9/202629/9/2026
luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as…
AplazadaMedia (4.3)0.18%—BlockspareAI19/9/202621/9/2026
The BlockSpare plugin for WordPress is vulnerable to authorization bypass due to incorrect logic in the permission callback in all versions up to, and including, 4.2.6 due to the use of an AND (&&) operator instead of an OR (||) operator. This makes it possible for authenticated attackers, with Subscriber-level access…
AplazadaAlta (8.8)0.51%—Master BlocksAI19/9/202621/9/2026
The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthenticated users to update its settings, including a value that is output unescaped in the admin area, leading to Stored XSS that executes in the session of any administrator visiting a wp-admin page.
AplazadaMedia (5.5)0.23%—Crocoblock JetformbuilderAI19/9/202621/9/2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server…
AplazadaMedia (6.6)0.39%—Areoi ALL Bootstrap BlocksAI18/9/202618/9/2026
The All Bootstrap Blocks WordPress plugin through 1.3.31 does not validate a block attribute before using it to build a filesystem path that is included at render time, allowing users with contributor-level access and above to include arbitrary local files, disclose their contents, and execute PHP where a local file…