Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.30% | — | Sender Newsletter SMS AND Email Marketing Automation FOR WoocommerceAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through… | |
| Aplazada | Alta (7.2) | 0.62% | — | News FlashAI | 8/8/2024 | 17/6/2026 | The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input from the newsflash_post_meta meta value. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known… | |
| Modificada | Media (4.3) | 0.38% | — | Icegram Email Subscribers & Newsletters | 17/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.55% | — | Automattic Newspack BlocksAI | 10/7/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8. | |
| Aplazada | Crítica (9.9) | 0.57% | — | Automattic Newspack BlocksAI | 9/7/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Automattic Newspack Blocks allows Upload a Web Shell to a Web Server.This issue affects Newspack Blocks: from n/a through 3.0.8. | |
| Modificada | Media (5.4) | 0.29% | — | Automattic Newspack ADS | 4/7/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Automattic Newspack Ads allows Stored XSS.This issue affects Newspack Ads: from n/a through 1.47.1. | |
| Modificada | Media (5.4) | 0.29% | — | Automattic Newspack Popups | 4/7/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Automattic Newspack Campaigns allows Stored XSS.This issue affects Newspack Campaigns: from n/a through 2.31.1. | |
| Modificada | Crítica (9.8) | 1.1% | — | Icegram Email Subscribers & Newsletters | 2/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Icegram Email Subscribers AND NewslettersAI | 26/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25. | |
| Analizada | Crítica (9.8) | 0.28% | — | Blossomthemes Email Newsletter | 26/6/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6. | |
| Aplazada | Baja (3.9) | 0.21% | — | UDN News Android APPAI | 25/6/2024 | 17/6/2026 | udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn. | |
| Aplazada | Baja (3.9) | 0.21% | — | UDN News Android APPAI | 25/6/2024 | 17/6/2026 | udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn. | |
| Modificada | Alta (8.8) | 0.23% | — | Tribulant Newsletters | 21/6/2024 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7. | |
| Modificada | Alta (8.8) | 0.21% | — | Blazethemes Digital Newspaper | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5. | |
| Modificada | Media (5.3) | 0.37% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 21/6/2024 | 17/6/2026 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (4.8) | 0.28% | — | Tagdiv Newspaper | 15/6/2024 | 17/6/2026 | The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 0.56% | — | Mayurik Best Online News Portal | 14/6/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (6.5) | 0.32% | — | Newsletter | 12/6/2024 | 17/6/2026 | The Newsletter - API v1 and v2 addon plugin for WordPress is vulnerable to unauthorized subscribers management due to PHP type juggling issue on the check_api_key function in all versions up to, and including, 2.4.5. This makes it possible for unauthenticated attackers to list, create or delete newsletter subscribers.… | |
| Modificada | Crítica (9.8) | 0.39% | — | Icegram Email Subscribers & Newsletters | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13. | |
| Modificada | Media (6.1) | 0.29% | — | Tribulant Newsletters | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 5/6/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (6.1) | 0.29% | — | Thenewsletterplugin Newsletter | 5/6/2024 | 17/6/2026 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Media (6.1) | 0.29% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77. | |
| Analizada | Media (6.9) | 0.81% | — | Oretnom23 Facebook News Feed Like | 27/5/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to sql injection. The attack can be initiated remotely. VDB-266302 is the identifier assigned to this vulnerability. | |
| Aplazada | Media (5.3) | 0.49% | — | Stefano Lissa AND THE Newsletter Team NewsletterAI | 17/5/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality Bypass.This issue affects Newsletter: from n/a through 8.2.0. |