Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
103 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.13% | — | Jetimpex JetengineAI | 30/9/2026 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3. | |
| Aplazada | Media (5.5) | 0.17% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Crocoblock JetengineAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.3 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 28/8/2026 | 28/8/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 20/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | |
| Aplazada | Crítica (9.8) | 0.86% | — | Crocoblock JetengineAI | 19/8/2026 | 20/8/2026 | Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. | |
| Aplazada | Media (6.8) | 0.43% | — | Crocoblock JetengineAI | 19/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing users with the upload files capability, such as Authors, to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Aplazada | Media (6.1) | 0.27% | — | Crocoblock JetengineAI | 10/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the browser of any user who opens it (Stored… | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions. | |
| Aplazada | Media (5.4) | 0.23% | — | Crocoblock JetengineAI | 2/8/2026 | 26/8/2026 | The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged users such as administrators. | |
| Aplazada | Media (4.9) | 0.19% | — | Crocoblock JetengineAI | 23/7/2026 | 23/7/2026 | Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 26/6/2026 | 29/6/2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.9.1 versions. | |
| Aplazada | Alta (7.5) | 0.32% | — | Crocoblock JetengineAI | 17/6/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 17/6/2026 | 28/9/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine jet-engine allows Blind SQL Injection.This issue affects JetEngine: from n/a through 3.8.9.1. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Crocoblock JetengineAI | 25/5/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetEngine allows SQL Injection. This issue affects JetEngine: from n/a through 3.8.8.1. | |
| Aplazada | Alta (7.5) | 0.46% | — | Crocoblock JetengineAI | 14/4/2026 | 17/6/2026 | The JetEngine plugin for WordPress is vulnerable to SQL Injection via the Custom Content Type (CCT) REST API search endpoint in all versions up to, and including, 3.8.6.1. This is due to the `_cct_search` parameter being interpolated directly into a SQL query string via `sprintf()` without sanitization or use of… | |
| Aplazada | Media (5.5) | 0.53% | — | Promptengineer LocalgptAI | 28/3/2026 | 17/6/2026 | A vulnerability was found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. This affects the function handle_index of the file rag_system/api_server.py of the component Web Interface. Performing a manipulation results in information disclosure. It is possible to initiate the attack remotely.… | |
| Aplazada | Media (5.5) | 0.52% | — | Promptengineer LocalgptAI | 28/3/2026 | 17/6/2026 | A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054. The impacted element is the function _route_using_overviews of the file backend/server.py of the component LLM Prompt Handler. Such manipulation leads to injection. The attack may be performed from remote. The… |