Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
263 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.24% | — | Crocoblock JetformbuilderAI | 2/10/2026 | 3/10/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'choice' Post Meta via Insert/Update Post Action in all versions up to, and including, 3.6.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated… | |
| Aplazada | Media (4.8) | 0.29% | — | Crocantickets EntradiumAI | 1/10/2026 | 1/10/2026 | CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during the process of creating discounts assigned to an event. This vulnerability allows JavaScript code to be injected into the… | |
| Aplazada | Media (4.8) | 0.28% | — | Crocantickets EntradiumAI | 1/10/2026 | 1/10/2026 | CVE-2026-7173: Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Exploitation of this vulnerability could allow a remote attacker to send a specially crafted URL to the victim and steal their session data. | |
| Aplazada | Alta (7.1) | 0.15% | — | Crocoblock JetformbuilderAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions. | |
| Aplazada | Media (5.5) | 0.17% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Media (6.1) | 0.21% | — | Crocoblock JetformbuilderAI | 25/9/2026 | 25/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'jfb_xss' (URL Query Variable) Parameter via Calculated Field in all versions up to, and including, 3.6.5.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.25% | — | Java110 MicrocommunityAI | 24/9/2026 | 24/9/2026 | A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBack of the file BusinessApi.java of the component fallBack API Endpoint. Such manipulation of the argument fallBackSql leads to sql injection. The attack may be launched remotely. The exploit is… | |
| Aplazada | Media (5.5) | 0.23% | — | Crocoblock JetformbuilderAI | 19/9/2026 | 21/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not sufficiently restrict which PHP functions can be used as a custom field-validation callback, relying on a blocklist that omits a file-deletion function, allowing users able to manage forms to cause arbitrary files on the server… | |
| Aplazada | Media (6.5) | 0.22% | — | Crocoblock Jetelements FOR ElementorAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Crocoblock JetformbuilderAI | 16/9/2026 | 17/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and… | |
| Pendiente de análisis | Media (5.6) | 0.20% | — | Microchip An1044AIMicrochip An953AIMicrochip Sw300052AI | 12/9/2026 | 16/9/2026 | Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN1044: through A; AN953: through A; SW300052: through 2.6. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetformbuilderAI | 8/9/2026 | 8/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions. | |
| Aplazada | Media (4.8) | 0.15% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headers of the e-mails it sends, allowing unauthenticated users to inject arbitrary e-mail headers, add hidden recipients and spoof the sender.… | |
| Aplazada | Media (6.5) | 0.20% | — | Crocoblock JetformbuilderAI | 6/9/2026 | 8/9/2026 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitrary shortcodes registered on the site on any page displaying a form. Escaping is applied to that content before a later shortcode-expansion… | |
| Aplazada | Media (4.7) | 0.17% | — | Crocoblock JetformbuilderAI | 5/9/2026 | 8/9/2026 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML notification emails it sends, allowing unauthenticated users to inject arbitrary HTML into messages delivered to administrators and other… | |
| Aplazada | Media (5.3) | 0.31% | — | Crocoblock JetpopupAI | 4/9/2026 | 4/9/2026 | Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a through 2.0.20.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 28/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | |
| Aplazada | Alta (7.3) | 0.14% | — | Microchip Sama5d4AI | 24/8/2026 | 31/8/2026 | Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | |
| Aplazada | Crítica (9.8) | 0.86% | — | Crocoblock JetengineAI | 19/8/2026 | 20/8/2026 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Crocoblock JetengineAI | 19/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Aplazada | Media (6.1) | 0.27% | — | Crocoblock JetengineAI | 10/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Aplazada | Alta (7.5) | 0.35% | — | Crocoblock JetformbuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. |