Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

101 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.1)0.30%—Netgate PfsenseAIPfblockerngAI25/9/202630/9/2026
Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package
AplazadaBaja (2.1)0.37%—Phpgurukul Bank Locker Management SystemAI13/9/202615/9/2026
A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to…
AplazadaBaja (2.1)0.37%—Phpgurukul Bank Locker Management SystemAI13/9/202614/9/2026
A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been released to the public and may be used…
AplazadaMedia (5.5)0.57%—Phpgurukul Bank Locker Management SystemAI13/9/202616/9/2026
A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is publicly available and might be used.
Pendiente de análisisMedia (6.9)0.44%—Ip2location Country BlockerAI9/9/20269/9/2026
IP2Location Country Blocker plugin for WordPress before 2.45.0 contains an access control bypass vulnerability that allows unauthenticated remote attackers to circumvent IP-based restrictions by forging the X-Real-IP HTTP header. Attackers can set the X-Real-IP header to an allowlisted IP address to bypass page, link,…
AplazadaMedia (4.6)0.16%—Iobit UnlockerAI31/8/202631/8/2026
A vulnerability has been found in IObit Unlocker 1.3.0.12. This vulnerability affects the function ZwTerminateProcess in the library IObitUnlocker.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation leads to improper privilege management. An attack has to be approached locally. The vendor was…
AplazadaCrítica (9.1)0.20%—Cpsd Cryptopro Secure Disk FOR BitlockerAILuksAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
AplazadaAlta (8.4)0.14%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for code execution in the context of high…
AplazadaAlta (7.5)0.49%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.
AplazadaCrítica (9.8)0.78%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.
AplazadaMedia (4.6)0.24%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 stores TPM2.0 secrets in a serialized format within unused disk sectors. An unauthenticated attacker with physical access to the system disk can recover this information and craft an environment to unseal the TPM.
AplazadaAlta (7.2)0.67%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for code execution in the context of high…
AplazadaAlta (7.5)0.19%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.
AplazadaCrítica (9.8)0.65%—Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.
AplazadaAlta (7.5)0.31%—Cpsd Cryptopro Secure Disk FOR BitlockerAI12/8/202629/9/2026
CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryptographic details.
AplazadaMedia (5.3)0.39%—Fense Proxy VPN BlockerAI17/7/202621/7/2026
The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to both wp_ajax_* and wp_ajax_nopriv_*…
AplazadaAlta (7.1)0.25%—Proxy & VPN BlockerAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proxy &amp; VPN Blocker Proxy &amp; VPN Blocker proxy-vpn-blocker allows Stored XSS.This issue affects Proxy &amp; VPN Blocker: from n/a through <= 3.5.8.
AplazadaAlta (7.1)0.25%—Inilerm Advanced IP BlockerAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IniLerm Advanced IP Blocker advanced-ip-blocker allows DOM-Based XSS.This issue affects Advanced IP Blocker: from n/a through <= 8.10.7.
AplazadaMedia (5.1)0.19%—Ip2location Country BlockerAI10/5/202624/7/2026
WordPress Plugin IP2Location Country Blocker 2.26.7 contains a stored cross-site scripting vulnerability that allows authenticated users to inject arbitrary JavaScript code through the Frontend Settings interface. Attackers can inject malicious scripts in the URL field of the Display page settings that execute when…
AplazadaMedia (5.4)0.18%—Dogblocker Minify HtmlAI31/3/202625/7/2026
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. This makes it possible for unauthenticated attackers to update plugin settings via a forged…
AplazadaBaja (2.1)0.47%—Lockerproject LockerAI11/3/202617/6/2026
A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of the file source-code/Locker-master/Ops/registry.js of the component Error Response Handler. The manipulation of the argument ID results in cross site scripting. The attack can be launched remotely.…
AplazadaMedia (6.1)0.27%—Xmlrpc Attacks BlockerAI19/2/202617/6/2026
The xmlrpc attacks blocker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0, via the 'X-Forwarded-For' HTTP header. This is due to the plugin trusting and logging attacker-controlled IP header data and rendering debug log entries without output escaping. This…
AplazadaMedia (4.3)0.18%—Country Blocker FOR AdsenseAI19/2/202617/6/2026
The Country Blocker for AdSense plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the CBFA_guardar_cbfa() function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged…
AnalizadaMedia (6.2)0.17%—Iobit Unlocker13/2/202617/6/2026
An issue in IObit Unlocker v1.3.0.11 allows attackers to cause a Denial of Service (DoS) via a crafted request.
AplazadaMedia (5.3)0.39%—Advanced Country BlockerAI7/2/202617/6/2026
The Advanced Country Blocker plugin for WordPress is vulnerable to Authorization Bypass in all versions up to, and including, 2.3.1 due to the use of a predictable default value for the secret bypass key created during installation without requiring users to change it. This makes it possible for unauthenticated…