Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.36% | — | Sumanbhattarai Send Users EmailAI | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Send Users Email: from n/a through 1.5.1. | |
| Aplazada | Alta (7.1) | 0.30% | — | Sender Newsletter SMS AND Email Marketing Automation FOR WoocommerceAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through… | |
| Aplazada | Media (5.3) | 0.48% | — | Obfuscate EmailAI | 12/8/2024 | 17/6/2026 | The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8.1. This is due to the plugin allowing direct access to the bootstrap.php file which has display_errors on. This makes it possible for unauthenticated attackers to retrieve the full path of the web… | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Email | 7/8/2024 | 17/6/2026 | Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information. | |
| Analizada | Media (5.9) | 0.21% | — | Yasirwazir Send Email Only ON Reply TO MY Comment | 30/7/2024 | 17/6/2026 | The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Analizada | Media (6.1) | 0.40% | — | Yasirwazir Send Email Only ON Reply TO MY Comment | 30/7/2024 | 17/6/2026 | The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Analizada | Media (5.4) | 0.38% | — | Wp-webhooks Email Encoder | 29/7/2024 | 17/6/2026 | The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading to a Stored Cross-Site Scripting | |
| Modificada | Media (4.8) | 0.28% | — | Dcurasi CC & BCC FOR Woocommerce Order Emails | 21/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dario Curasì CC & BCC for Woocommerce Order Emails allows Stored XSS.This issue affects CC & BCC for Woocommerce Order Emails: from n/a through 1.4.1. | |
| Aplazada | Media (5.9) | 0.27% | — | Marian Kadanka Change From EmailAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marian Kadanka Change From Email allows Stored XSS.This issue affects Change From Email: from n/a through 1.2.1. | |
| Analizada | Crítica (9.8) | 2.3% | — | Cisco Secure Email Gateway | 17/7/2024 | 17/6/2026 | A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is due to improper handling of email attachments when file analysis and content… | |
| Modificada | Media (4.3) | 0.38% | — | Icegram Email Subscribers & Newsletters | 17/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.77% | — | Cellopoint Secure Email Gateway | 15/7/2024 | 17/6/2026 | The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server. | |
| Aplazada | Alta (7.1) | 0.23% | — | Wpjohnny Comment Reply EmailAI | 12/7/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Comment Reply Email: from n/a through 1.3. | |
| Modificada | Crítica (9.8) | 1.1% | — | Icegram Email Subscribers & Newsletters | 2/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Icegram Email Subscribers AND NewslettersAI | 26/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25. | |
| Analizada | Crítica (9.8) | 0.28% | — | Blossomthemes Email Newsletter | 26/6/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6. | |
| Modificada | Media (5.3) | 0.37% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 21/6/2024 | 17/6/2026 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tag_subscriber function in all versions up to, and including, 2.4.9. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.3) | 0.38% | — | Wedevs Wemail | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in weDevs weMail.This issue affects weMail: from n/a through 1.14.2. | |
| Modificada | Crítica (9.8) | 0.39% | — | Icegram Email Subscribers & Newsletters | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13. | |
| Modificada | Alta (8.5) | 0.54% | — | Emailgpt | 5/6/2024 | 17/6/2026 | The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service logic. Attackers can exploit the issue by forcing the AI service to leak the standard hard-coded system prompts and/or execute unwanted… | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 5/6/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Modificada | Media (6.1) | 0.29% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 4/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows Reflected XSS.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.77. | |
| Analizada | Media (6.5) | 0.31% | — | Codepeople Contact Form Email | 4/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in CodePeople Contact Form Email allows Functionality Bypass.This issue affects Contact Form Email: from n/a through 1.3.41. | |
| Analizada | Media (4.3) | 0.31% | — | Codepeople Contact Form Email | 4/6/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Contact Form Email allows Functionality Misuse.This issue affects Contact Form Email: from n/a through 1.3.31. | |
| Aplazada | Alta (8.1) | 0.82% | — | Email LOGAI | 24/5/2024 | 17/6/2026 | The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to… |