Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.1) | 0.30% | — | Netgate PfsenseAIPfblockerngAI | 25/9/2026 | 30/9/2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 15/9/2026 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to… | |
| Aplazada | Baja (2.1) | 0.37% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 14/9/2026 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used… | |
| Aplazada | Media (5.5) | 0.57% | — | Phpgurukul Bank Locker Management SystemAI | 13/9/2026 | 16/9/2026 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Pendiente de análisis | Media (6.9) | 0.44% | — | Ip2location Country BlockerAI | 9/9/2026 | 9/9/2026 | IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link,… | |
| Aplazada | Media (4.6) | 0.16% | — | Iobit UnlockerAI | 31/8/2026 | 31/8/2026 | A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| Aplazada | Alta (8.4) | 0.14% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.49% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext. | |
| Aplazada | Crítica (9.8) | 0.78% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform. | |
| Aplazada | Media (4.6) | 0.24% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM. | |
| Aplazada | Alta (7.2) | 0.67% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high… | |
| Aplazada | Alta (7.5) | 0.19% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped. | |
| Aplazada | Crítica (9.8) | 0.65% | — | Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations. | |
| Aplazada | Alta (7.5) | 0.31% | — | Cpsd Cryptopro Secure Disk FOR BitlockerAI | 12/8/2026 | 29/9/2026 | CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details. | |
| Aplazada | Media (5.3) | 0.39% | — | Fense Proxy VPN BlockerAI | 17/7/2026 | 21/7/2026 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*… | |
| Aplazada | Alta (7.1) | 0.25% | — | Proxy & VPN BlockerAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy & VPN Blocker Proxy & VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy & VPN Blocker: from n/a through <= 3.5.8. | |
| Aplazada | Alta (7.1) | 0.25% | — | Inilerm Advanced IP BlockerAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7. | |
| Aplazada | Media (5.1) | 0.19% | — | Ip2location Country BlockerAI | 10/5/2026 | 24/7/2026 | WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when… | |
| Aplazada | Media (5.4) | 0.18% | — | Dogblocker Minify HtmlAI | 31/3/2026 | 25/7/2026 | The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged… | |
| Aplazada | Baja (2.1) | 0.47% | — | Lockerproject LockerAI | 11/3/2026 | 17/6/2026 | A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry.js of the component Error Response Handler. The manipulation of the argument ID results in cross site scripting. The attack can be launched remotely.… | |
| Aplazada | Media (6.1) | 0.27% | — | Xmlrpc Attacks BlockerAI | 19/2/2026 | 17/6/2026 | The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This… | |
| Aplazada | Media (4.3) | 0.18% | — | Country Blocker FOR AdsenseAI | 19/2/2026 | 17/6/2026 | The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the CBFA_guardar_cbfa() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged… | |
| Analizada | Media (6.2) | 0.17% | — | Iobit Unlocker | 13/2/2026 | 17/6/2026 | An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Aplazada | Media (5.3) | 0.39% | — | Advanced Country BlockerAI | 7/2/2026 | 17/6/2026 | The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and including, 2.3.1 due to the use of a predictable default value for the secret bypass key created during installation without requiring users to change it. This makes it possible for unauthenticated… |