Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAIHttp4s-ember-serverAITypelevel Http4sAI | 15/9/2026 | 16/9/2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote client that completes a WebSocket… | |
| Aplazada | Alta (7.4) | 0.63% | — | Typelevel BlazeAI | 14/9/2026 | 30/9/2026 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary… | |
| Aplazada | Alta (7.8) | 0.33% | — | Backblaze ClientAIMicrosoft WindowsAI | 1/9/2026 | 11/9/2026 | A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls.… | |
| Aplazada | Alta (7.4) | 0.48% | — | Typelevel BlazeAITypelevel Http4sAI | 12/8/2026 | 9/9/2026 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote client can inject arbitrary header names… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Http4s-blaze-serverAI | 12/8/2026 | 10/9/2026 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket handshake can send an unterminated… | |
| Aplazada | Alta (7.1) | 0.13% | — | Gncc GP5AIBackblaze B2AI | 4/6/2026 | 22/7/2026 | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface. | |
| Aplazada | Media (4.3) | 0.19% | — | Blazethemes News KIT Elementor AddonsAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2. | |
| Aplazada | Crítica (9.9) | 0.54% | — | Blazethemes BlogzeeAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogzee blogzee allows Using Malicious Files.This issue affects Blogzee: from n/a through <= 1.0.5. | |
| Aplazada | Crítica (9.9) | 0.54% | — | Blazethemes BlogisticAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogistic blogistic allows Using Malicious Files.This issue affects Blogistic: from n/a through <= 1.0.5. | |
| Aplazada | Crítica (9.9) | 0.54% | — | Blazethemes News EventAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1. | |
| Aplazada | Crítica (9.9) | 0.54% | — | Blazethemes BlogmaticAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes Blogmatic blogmatic.This issue affects Blogmatic: from n/a through <= 1.0.3. | |
| Aplazada | Alta (8.1) | 0.27% | — | Blaze Demo ImporterAI | 12/12/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1.0.13. This makes it possible for authenticated attackers, with subscriber level… | |
| Aplazada | Media (4.3) | 0.23% | — | Blaze Demo ImporterAI | 16/9/2025 | 17/6/2026 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capability check on the 'blaze_demo_importer_install_plugin' function in all versions up to, and including, 1.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Alta (8.6) | 1.2% | — | Blazevideo Hdtv Player PROAI | 5/8/2025 | 16/6/2026 | BlazeVideo HDTV Player Pro v6.6.0.3 is vulnerable to a stack-based buffer overflow due to improper handling of user-supplied input embedded in .plf playlist files. When parsing a crafted .plf file, the MediaPlayerCtrl.dll component invokes PathFindFileNameA() to extract a filename from a URL-like string. The returned… | |
| Aplazada | Media (5.4) | 0.22% | — | Blazethemes News KIT Elementor AddonsAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.3.4. | |
| Aplazada | Alta (7.1) | 0.27% | — | Blaze Concepts Better Customer List FOR WoocommerceAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blaze Concepts Better Customer List for WooCommerce woo-better-customer-list allows Reflected XSS.This issue affects Better Customer List for WooCommerce: from n/a through <= 1.2.3. | |
| Aplazada | Media (6.5) | 0.39% | — | Blazethemes News KIT Elementor AddonsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Stored XSS.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.19% | — | Blazethemes Trendy NewsAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Trendy News trendy-news allows Cross Site Request Forgery.This issue affects Trendy News: from n/a through <= 1.0.15. | |
| Aplazada | Alta (7.1) | 0.44% | — | Blazeonline Blaze Online Eparcel FOR WoocommerceAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazeonline Blaze Online eParcel for WooCommerce blaze-online-eparcel-for-woocommerce allows Reflected XSS.This issue affects Blaze Online eParcel for WooCommerce: from n/a through <= 1.3.3. | |
| Aplazada | Media (6.5) | 0.31% | — | Blazethemes News KIT Elementor AddonsAI | 9/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Stored XSS.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2. | |
| Aplazada | Media (5.3) | 0.38% | — | Blazethemes NewsmaticAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in blazethemes Newsmatic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Newsmatic: from n/a through 1.3.1. | |
| Analizada | Media (4.3) | 0.34% | — | Blazethemes News KIT Elementor Addons | 22/10/2024 | 17/6/2026 | The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render function in includes/widgets/canvas-menu/canvas-menu.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract… | |
| Modificada | Alta (8.8) | 0.21% | — | Blazethemes Digital Newspaper | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5. | |
| Modificada | Media (5.3) | 0.58% | — | Blazethemes Newsmatic | 9/4/2024 | 17/6/2026 | The Newsmatic theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.0 via the 'newsmatic_filter_posts_load_tab_content'. This makes it possible for unauthenticated attackers to view draft posts and post content. | |
| Modificada | Alta (7.5) | 0.89% | — | Blazer Project Blazer | 21/4/2022 | 17/6/2026 | Blazer before 2.6.0 allows SQL Injection. In certain circumstances, an attacker could get a user to run a query they would not have normally run. |