Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.54% | — | Phpkobo Ajaxnewsticker | 27/9/2023 | 9/7/2026 | Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component. | |
| Modificada | Media (6.1) | 0.66% | — | Phpkobo Ajaxnewsticker | 27/9/2023 | 9/7/2026 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component. | |
| Modificada | Crítica (9.8) | 1.4% | — | Phpkobo Ajaxnewsticker | 27/9/2023 | 9/7/2026 | An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | |
| Modificada | Media (6.1) | 0.70% | — | Phpkobo Ajaxnewsticker | 27/9/2023 | 9/7/2026 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component. | |
| Modificada | Media (6.1) | 0.61% | — | Phpkobo Ajaxnewsticker | 27/9/2023 | 9/7/2026 | Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component. | |
| Modificada | Media (6.1) | 0.41% | — | Everestthemes Everest News | 27/9/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Everest News Pro theme <= 1.1.7 versions. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Fieldthemes Fieldpopupnewsletter | 8/9/2023 | 17/6/2026 | FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php. | |
| Modificada | Media (5.4) | 0.51% | — | Thenewsletterplugin Newsletter | 7/9/2023 | 17/6/2026 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'newsletter_form' shortcode in versions up to, and including, 7.8.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level… | |
| Modificada | Media (6.1) | 0.41% | — | Everestthemes Everest News | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest themes Everest News theme <= 1.1.0 versions. | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts Newsletter Script PHP | 7/7/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The identifier of… | |
| Modificada | Media (6.1) | 0.36% | — | Simplephpscripts News Script PHP PRO | 7/7/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an unknown part of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The identifier VDB-233289… | |
| Modificada | Media (5.5) | 0.17% | — | Uzabase Newspicks | 30/6/2023 | 17/6/2026 | "NewsPicks" App for Android versions 10.4.5 and earlier and "NewsPicks" App for iOS versions 10.4.2 and earlier use hard-coded credentials, which may allow a local attacker to analyze data in the app and to obtain API key for an external service. | |
| Modificada | Crítica (9.8) | 1.6% | — | Xyzscripts Newsletter Manager | 7/6/2023 | 17/6/2026 | The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.5) | 0.97% | — | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+11 | 7/6/2023 | 17/6/2026 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and… | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+12 | 7/6/2023 | 17/6/2026 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=… | |
| Modificada | Media (6.1) | 0.49% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 5/6/2023 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against… | |
| Modificada | Media (6.1) | 0.46% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 5/6/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.55% | — | Eelv Newsletter Project Eelv Newsletter | 4/6/2023 | 16/6/2026 | A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. It has been rated as problematic. Affected by this issue is the function style_newsletter of the file lettreinfo.php. The manipulation of the argument email leads to cross site scripting. The attack may be launched remotely. The name of the patch is… | |
| Modificada | Alta (8.8) | 0.39% | — | Newsletter Popup Project Newsletter Popup | 30/5/2023 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks as the wp_newsletter_show_localrecord page is not protected with a nonce. | |
| Modificada | Media (6.1) | 0.51% | — | Newsletter Popup Project Newsletter Popup | 30/5/2023 | 17/6/2026 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Thenewsletterplugin Newsletter | 23/5/2023 | 17/6/2026 | Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script. | |
| Modificada | Media (5.4) | 0.37% | — | Machothemes Newsmag | 8/5/2023 | 17/6/2026 | Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Te-st Yandex.news Feed BY Teplitsa | 8/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Teplitsa Yandex.News Feed by Teplitsa plugin <= 1.12.5 versions. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Idnovate Popup Module (ON Entering, Exit Popup, ADD Product) AND Newsletter | 12/4/2023 | 17/6/2026 | Prestashop advancedpopupcreator v1.1.21 to v1.1.24 was discovered to contain a SQL injection vulnerability via the component AdvancedPopup::getPopups(). | |
| Modificada | Crítica (9.8) | 0.81% | — | Mayurik Best Online News Portal | 9/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/forgot-password.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack can be… |