Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.83%—Tagdiv Newspaper19/7/202117/6/2026
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
ModificadaMedia (6.1)0.75%—Ec-cube Email Newsletters Management22/6/202117/6/2026
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
ModificadaMedia (6.1)2.0%💥 ExploitJnews7/6/202117/6/2026
The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue.
ModificadaMedia (4.8)0.63%—Online News Portal Project Online News Portal26/1/202117/6/2026
Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter.
ModificadaMedia (6.5)0.86%—Thenewsletterplugin Newsletter1/1/202117/6/2026
A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the…
ModificadaAlta (8.8)2.1%—Tribulant Newsletter1/1/202117/6/2026
Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that…
ModificadaMedia (4.8)0.62%💥 PoCNetartmedia News Lister30/11/202017/6/2026
In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles.
ModificadaCrítica (9.8)1.1%—Newsscriptphp News Script PHP PRO24/11/202017/6/2026
SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action.
ModificadaMedia (6.1)0.87%—Newsscriptphp News Script PHP PRO24/11/202017/6/2026
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter.
ModificadaMedia (6.5)0.92%—Newsscriptphp News Script PHP PRO24/11/202017/6/2026
SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies.
ModificadaMedia (6.5)0.52%—Newsscriptphp News Script PHP PRO24/11/202017/6/2026
SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users.
ModificadaMedia (6.1)0.65%—SAP Fiori Launchpad (news Tile Application)13/11/202017/6/2026
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected…
ModificadaAlta (8.6)1.4%—SAP Fiori Launchpad (news Tile Application)10/11/202017/6/2026
SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve…
ModificadaMedia (5.3)1.6%—Icegram Email Subscribers & Newsletters10/9/202017/6/2026
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
ModificadaCrítica (9.8)3.1%—Calendar01 Project Calendar01Calendar02 Project Calendar02Calendarform01 Project Calendarform01Gallery01 Project Gallery01+44/8/202017/6/2026
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0,…
ModificadaMedia (4.9)2.0%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
ModificadaMedia (6.5)0.92%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
ModificadaAlta (7.8)0.65%—Sourcefabric Newscoop19/5/202017/6/2026
Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path.
ModificadaAlta (8.8)2.1%—Cutephp Cutenews25/3/202017/6/2026
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
ModificadaMedia (6.1)0.77%—Cutephp Cutenews25/3/202017/6/2026
Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaCrítica (9.8)8.9%💥 ExploitThemerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+5910/3/202017/6/2026
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
ModificadaAlta (7.2)0.98%—Joobi Jnews9/3/202017/6/2026
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.
ModificadaAlta (8.8)1.1%—Joobi Jnews9/3/202017/6/2026
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
ModificadaCrítica (9.8)1.4%—Magento Advanced Newsletter9/3/202017/6/2026
SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO.
ModificadaMedia (4.8)0.54%—Joobi Jnews9/3/202017/6/2026
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
Orbitaley — Vulnerabilidades