Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.39%—Icegram Email Subscribers AND NewslettersAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
AplazadaMedia (4.3)0.50%—Hashthemes Viral NewsAIHashthemes ViralAIHashthemes HashoneAI25/3/202417/6/2026
Missing Authorization vulnerability in HashThemes Viral News, HashThemes Viral, HashThemes HashOne.This issue affects Viral News: from n/a through 1.4.5; Viral: from n/a through 1.8.0; HashOne: from n/a through 1.3.0.
ModificadaAlta (8.8)0.77%—Storeapps News Announcement Scroll13/3/202417/6/2026
The News Announcement Scroll plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 9.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated…
ModificadaMedia (5.4)0.30%—Newsletter2go12/3/202417/6/2026
The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber access and above, to inject…
AnalizadaAlta (7.5)0.45%—Webbax Super Newsletter3/3/202417/6/2026
An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive information.
ModificadaMedia (5.4)0.31%—Primitiv PJ News Ticker29/2/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicolas Montigny PJ News Ticker allows Stored XSS.This issue affects PJ News Ticker: from n/a through 1.9.5.
ModificadaMedia (6.1)0.36%—Oretnom23 Facebook News Feed Like30/1/202417/6/2026
A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Post Handler. The manipulation of the argument Description with the input <marquee>HACKED</marquee> leads to cross site scripting. The…
ModificadaCrítica (9.8)0.47%—Oretnom23 Facebook News Feed Like30/1/202417/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is an unknown function of the component Post Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-252300.
ModificadaMedia (6.1)0.31%—Oretnom23 Facebook News Feed Like30/1/202417/6/2026
A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New Account Handler. The manipulation of the argument First Name/Last Name with the input <script>alert(1)</script> leads to cross site scripting. The…
ModificadaAlta (7.2)0.96%—Tribulant Newsletters16/1/202417/6/2026
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
ModificadaMedia (5.4)0.43%—Gopiplus Jquery News Ticker19/12/202317/6/2026
The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (7.2)0.96%—Alphabpo Easy Newsletter Signups4/12/202317/6/2026
The Easy Newsletter Signups WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
ModificadaCrítica (9.8)4.3%💥 ExploitInfornweb News & Blog Designer Pack22/11/202317/6/2026
The News & Blog Designer Pack – WordPress Blog Plugin — (Blog Post Grid, Blog Post Slider, Blog Post Carousel, Blog Post Ticker, Blog Post Masonry) plugin for WordPress is vulnerable to Remote Code Execution via Local File Inclusion in all versions up to, and including, 3.4.1 via the bdp_get_more_post function hooked…
ModificadaAlta (8.8)0.38%—Bdaia Woohoo Newspaper Magazine Theme20/11/202317/6/2026
The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaAlta (8.8)0.26%—Kibokolabs Arigato Autoresponder AND Newsletter16/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter plugin <= 2.7.2.2 versions.
ModificadaCrítica (9.8)0.70%—Activedesign Newsletterpop15/11/202317/6/2026
In the module "Newsletter Popup PRO with Voucher/Coupon code" (newsletterpop) before version 2.6.1 from Active Design for PrestaShop, a guest can perform SQL injection in affected versions. The method `NewsletterpopsendVerificationModuleFrontController::checkEmailSubscription()` has sensitive SQL calls that can be…
ModificadaAlta (8.8)0.30%—Tribulant Newsletters10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
ModificadaMedia (6.5)0.79%—Gopiplus WP Fade IN Text News31/10/202317/6/2026
The WP fade in text news plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 12.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers…
ModificadaMedia (6.5)0.79%—Gopiplus Jquery News Ticker31/10/202317/6/2026
The Jquery news ticker plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 3.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with…
ModificadaMedia (5.4)0.40%—Happybox Newsletter & Bulk Email Sender25/10/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions.
ModificadaAlta (8.8)0.26%—Daext Live News9/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in DAEXT Live News plugin <= 1.06 versions.
ModificadaAlta (8.8)1.2%—Phpkobo Ajaxnewsticker28/9/20239/7/2026
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
ModificadaMedia (6.1)0.66%—Phpkobo Ajaxnewsticker28/9/20239/7/2026
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.
ModificadaMedia (6.1)0.66%—Phpkobo Ajaxnewsticker28/9/20239/7/2026
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
ModificadaMedia (6.1)0.66%—Phpkobo Ajaxnewsticker27/9/20239/7/2026
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.
Orbitaley — Vulnerabilidades