Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.37% | — | Icegram Email SubscribersAI | 23/5/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possible… | |
| Analizada | Alta (7.8) | 0.40% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security | 22/5/2024 | 17/6/2026 | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this… | |
| Analizada | Media (4.8) | 0.29% | — | Cisco AsyncosCisco Secure Email AND WEB Manager Virtual Appliance M100vCisco Secure Email AND WEB Manager Virtual Appliance M300vCisco Secure Email AND WEB Manager Virtual Appliance M600v | 15/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to conduct an XSS attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An… | |
| Aplazada | Alta (8.8) | 0.39% | — | Icegram Email SubscribersAI | 15/5/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.5) | 0.15% | — | Samsung Email | 7/5/2024 | 17/6/2026 | Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information. | |
| Analizada | Alta (7.5) | 1.1% | — | Rjbs Email-mimeFedoraproject Fedora | 2/5/2024 | 17/6/2026 | An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts. | |
| Aplazada | Crítica (9.8) | 81% | 💥 Exploit | Icegram Email SubscribersAI | 2/5/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user… | |
| Aplazada | Alta (8.1) | 0.85% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 30/4/2024 | 17/6/2026 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 via the use of insufficiently random activation code. This makes it possible for unauthenticated attackers to bypass the email verification, and… | |
| Analizada | Baja (3.8) | 0.20% | — | Mmilan81 Mm-email2image | 26/4/2024 | 17/6/2026 | The MM-email2image WordPress plugin through 0.2.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Analizada | Alta (8.1) | 0.62% | — | Mmilan81 Mm-email2image | 26/4/2024 | 17/6/2026 | The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Aplazada | Alta (7.5) | 0.68% | — | Themehigh Email Customizer FOR WoocommerceAI | 24/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ThemeHigh Email Customizer for WooCommerce.This issue affects Email Customizer for WooCommerce: from n/a through 2.6.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend omnisend-connect.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through <= 1.14.3. | |
| Aplazada | Media (4.3) | 0.20% | — | Coded Commerce LLC Benchmark Email LiteAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Coded Commerce, LLC Benchmark Email Lite.This issue affects Benchmark Email Lite: from n/a through 4.1. | |
| Modificada | Media (5.3) | 0.47% | — | Codepeople Contact Form Email | 10/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue affects Contact Form Email: from n/a through 1.3.44. | |
| Modificada | Alta (7.5) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 10/4/2024 | 12/8/2026 | Insertion of Sensitive Information into Log File vulnerability in ConvertKit.This issue affects ConvertKit: from n/a through 2.4.5. | |
| Aplazada | Media (4.4) | 0.35% | — | Icegram Email SubscribersAI | 6/4/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (5.4) | 0.37% | — | Cisco Enterprise Chat AND Email | 3/4/2024 | 17/6/2026 | A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit… | |
| Aplazada | Media (6.5) | 0.33% | — | Sayandatta Ultimate Social Comments Email Notification Lazy LoadAI | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta Ultimate Social Comments – Email Notification & Lazy Load allows Stored XSS.This issue affects Ultimate Social Comments – Email Notification & Lazy Load: from n/a through 1.4.8. | |
| Aplazada | Media (5.9) | 0.36% | — | Aminur Islam WP Change Email SenderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: from n/a before 1.3.0. | |
| Aplazada | Alta (7.1) | 0.39% | — | Icegram Email Subscribers AND NewslettersAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11. | |
| Aplazada | Alta (8.1) | 0.73% | — | Check AND LOG EmailAI | 26/3/2024 | 17/6/2026 | The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker… | |
| Modificada | Media (6.1) | 0.33% | — | I13websolution Email Subscription Popup | 17/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Email Subscription Popup allows Stored XSS.This issue affects Email Subscription Popup: from n/a through 1.2.20. | |
| Aplazada | Media (4.9) | 0.90% | — | Sonicwall Email Security ApplianceAI | 14/3/2024 | 17/6/2026 | An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance file system. | |
| Analizada | Alta (8.8) | 0.28% | — | Mandsconsulting Email Before Download | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7. | |
| Modificada | Media (5.4) | 0.44% | — | Onlineoptimisation Email Encoder | 29/2/2024 | 22/7/2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… |