Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.36%—Sumanbhattarai Send Users EmailAI13/8/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Send Users Email: from n/a through 1.5.1.
AplazadaAlta (7.1)0.30%—Sender Newsletter SMS AND Email Marketing Automation FOR WoocommerceAI12/8/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through…
AplazadaMedia (5.3)0.48%—Obfuscate EmailAI12/8/202417/6/2026
The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web…
AnalizadaMedia (5.5)0.13%—Samsung Email7/8/202417/6/2026
Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.
AnalizadaMedia (5.9)0.21%—Yasirwazir Send Email Only ON Reply TO MY Comment30/7/202417/6/2026
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaMedia (6.1)0.40%—Yasirwazir Send Email Only ON Reply TO MY Comment30/7/202417/6/2026
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
AnalizadaMedia (5.4)0.38%—Wp-webhooks Email Encoder29/7/202417/6/2026
The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting
ModificadaMedia (4.8)0.28%—Dcurasi CC & BCC FOR Woocommerce Order Emails21/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dario Curasì CC & BCC for Woocommerce Order Emails allows Stored XSS.This issue affects CC & BCC for Woocommerce Order Emails: from n/a through 1.4.1.
AplazadaMedia (5.9)0.27%—Marian Kadanka Change From EmailAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marian Kadanka Change From Email allows Stored XSS.This issue affects Change From Email: from n/a through 1.2.1.
AnalizadaCrítica (9.8)2.3%—Cisco Secure Email Gateway17/7/202417/6/2026
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handling of email attachments when file analysis and content…
ModificadaMedia (4.3)0.38%—Icegram Email Subscribers & Newsletters17/7/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)0.77%—Cellopoint Secure Email Gateway15/7/202417/6/2026
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.
AplazadaAlta (7.1)0.23%—Wpjohnny Comment Reply EmailAI12/7/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Comment Reply Email: from n/a through 1.3.
ModificadaCrítica (9.8)1.1%—Icegram Email Subscribers & Newsletters2/7/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of…
AplazadaCrítica (9.3)0.54%—Icegram Email Subscribers AND NewslettersAI26/6/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
AnalizadaCrítica (9.8)0.28%—Blossomthemes Email Newsletter26/6/202417/6/2026
Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6.
ModificadaMedia (5.3)0.37%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages21/6/202417/6/2026
The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to…
ModificadaMedia (5.3)0.38%—Wedevs Wemail11/6/202417/6/2026
Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2.
ModificadaCrítica (9.8)0.39%—Icegram Email Subscribers & Newsletters9/6/202417/6/2026
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
ModificadaAlta (8.5)0.54%—Emailgpt5/6/202417/6/2026
The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted…
ModificadaCrítica (9.8)10%💥 ExploitIcegram Email Subscribers & Newsletters5/6/202417/6/2026
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
ModificadaMedia (6.1)0.29%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe4/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77.
AnalizadaMedia (6.5)0.31%—Codepeople Contact Form Email4/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41.
AnalizadaMedia (4.3)0.31%—Codepeople Contact Form Email4/6/202417/6/2026
Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31.
AplazadaAlta (8.1)0.82%—Email LOGAI24/5/202417/6/2026
The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to…
Orbitaley — Vulnerabilidades