Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.37%—Icegram Email SubscribersAI23/5/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possible…
AnalizadaAlta (7.8)0.40%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security22/5/202417/6/2026
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this…
AnalizadaMedia (4.8)0.29%—Cisco AsyncosCisco Secure Email AND WEB Manager Virtual Appliance M100vCisco Secure Email AND WEB Manager Virtual Appliance M300vCisco Secure Email AND WEB Manager Virtual Appliance M600v15/5/202417/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An…
AplazadaAlta (8.8)0.39%—Icegram Email SubscribersAI15/5/202417/6/2026
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with…
AnalizadaMedia (5.5)0.15%—Samsung Email7/5/202417/6/2026
Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.
AnalizadaAlta (7.5)1.1%—Rjbs Email-mimeFedoraproject Fedora2/5/202417/6/2026
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
AplazadaCrítica (9.8)81%💥 ExploitIcegram Email SubscribersAI2/5/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user…
AplazadaAlta (8.1)0.85%—Wpfactory Customer Email Verification FOR WoocommerceAI30/4/202417/6/2026
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and…
AnalizadaBaja (3.8)0.20%—Mmilan81 Mm-email2image26/4/202417/6/2026
The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack
AnalizadaAlta (8.1)0.62%—Mmilan81 Mm-email2image26/4/202417/6/2026
The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
AplazadaAlta (7.5)0.68%—Themehigh Email Customizer FOR WoocommerceAI24/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeHigh Email Customizer for WooCommerce.This issue affects Email Customizer for WooCommerce: from n/a through 2.6.0.
AplazadaMedia (4.3)0.21%—Omnisend Email Marketing FOR WoocommerceAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend omnisend-connect.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through <= 1.14.3.
AplazadaMedia (4.3)0.20%—Coded Commerce LLC Benchmark Email LiteAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Coded Commerce, LLC Benchmark Email Lite.This issue affects Benchmark Email Lite: from n/a through 4.1.
ModificadaMedia (5.3)0.47%—Codepeople Contact Form Email10/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44.
ModificadaAlta (7.5)0.53%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages10/4/202412/8/2026
Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5.
AplazadaMedia (4.4)0.35%—Icegram Email SubscribersAI6/4/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it…
AnalizadaMedia (5.4)0.37%—Cisco Enterprise Chat AND Email3/4/202417/6/2026
A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit…
AplazadaMedia (6.5)0.33%—Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI31/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8.
AplazadaMedia (5.9)0.36%—Aminur Islam WP Change Email SenderAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: from n/a before 1.3.0.
AplazadaAlta (7.1)0.39%—Icegram Email Subscribers AND NewslettersAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
AplazadaAlta (8.1)0.73%—Check AND LOG EmailAI26/3/202417/6/2026
The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker…
ModificadaMedia (6.1)0.33%—I13websolution Email Subscription Popup17/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Email Subscription Popup allows Stored XSS.This issue affects Email Subscription Popup: from n/a through 1.2.20.
AplazadaMedia (4.9)0.90%—Sonicwall Email Security ApplianceAI14/3/202417/6/2026
An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system.
AnalizadaAlta (8.8)0.28%—Mandsconsulting Email Before Download29/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7.
ModificadaMedia (5.4)0.44%—Onlineoptimisation Email Encoder29/2/202422/7/2026
The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…