Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.83% | — | Tagdiv Newspaper | 19/7/2021 | 17/6/2026 | An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call. | |
| Modificada | Media (6.1) | 0.75% | — | Ec-cube Email Newsletters Management | 22/6/2021 | 17/6/2026 | Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation. | |
| Modificada | Media (6.1) | 2.0% | 💥 Exploit | Jnews | 7/6/2021 | 17/6/2026 | The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (with action=jnews_build_mega_category_*), leading to a Reflected Cross-Site Scripting (XSS) issue. | |
| Modificada | Media (4.8) | 0.63% | — | Online News Portal Project Online News Portal | 26/1/2021 | 17/6/2026 | Online News Portal using PHP/MySQLi 1.0 is affected by cross-site scripting (XSS) which allows remote attackers to inject an arbitrary web script or HTML via the "Title" parameter. | |
| Modificada | Media (6.5) | 0.86% | — | Thenewsletterplugin Newsletter | 1/1/2021 | 17/6/2026 | A Reflected Authenticated Cross-Site Scripting (XSS) vulnerability in the Newsletter plugin before 6.8.2 for WordPress allows remote attackers to trick a victim into submitting a tnpc_render AJAX request containing either JavaScript in an options parameter, or a base64-encoded JSON string containing JavaScript in the… | |
| Modificada | Alta (8.8) | 2.1% | — | Tribulant Newsletter | 1/1/2021 | 17/6/2026 | Insecure Deserialization in the Newsletter plugin before 6.8.2 for WordPress allows authenticated remote attackers with minimal privileges (such as subscribers) to use the tpnc_render AJAX action to inject arbitrary PHP objects via the options[inline_edits] parameter. NOTE: exploitability depends on PHP objects that… | |
| Modificada | Media (4.8) | 0.62% | 💥 PoC | Netartmedia News Lister | 30/11/2020 | 17/6/2026 | In NetArt News Lister 1.0.0, the news headlines vulnerable to stored xss attacks. Attackers can inject codes in news titles. | |
| Modificada | Crítica (9.8) | 1.1% | — | Newsscriptphp News Script PHP PRO | 24/11/2020 | 17/6/2026 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a SQL Injection via the id parameter in an editNews action. | |
| Modificada | Media (6.1) | 0.87% | — | Newsscriptphp News Script PHP PRO | 24/11/2020 | 17/6/2026 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Scripting (XSS) vulnerability via the editor_name parameter. | |
| Modificada | Media (6.5) | 0.92% | — | Newsscriptphp News Script PHP PRO | 24/11/2020 | 17/6/2026 | SimplePHPscripts News Script PHP Pro 2.3 does not properly set the HttpOnly Flag from Session Cookies. | |
| Modificada | Media (6.5) | 0.52% | — | Newsscriptphp News Script PHP PRO | 24/11/2020 | 17/6/2026 | SimplePHPscripts News Script PHP Pro 2.3 is affected by a Cross Site Request Forgery (CSRF) vulnerability, which allows attackers to add new users. | |
| Modificada | Media (6.1) | 0.65% | — | SAP Fiori Launchpad (news Tile Application) | 13/11/2020 | 17/6/2026 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to use SAP Fiori Launchpad News tile Application to send malicious code, to a different end user (victim), because News tile does not sufficiently encode user controlled inputs, resulting in Reflected… | |
| Modificada | Alta (8.6) | 1.4% | — | SAP Fiori Launchpad (news Tile Application) | 10/11/2020 | 17/6/2026 | SAP Fiori Launchpad (News tile Application), versions - 750,751,752,753,754,755, allows an unauthorized attacker to send a crafted request to a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network to retrieve… | |
| Modificada | Media (5.3) | 1.6% | — | Icegram Email Subscribers & Newsletters | 10/9/2020 | 17/6/2026 | Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing. | |
| Modificada | Crítica (9.8) | 3.1% | — | Calendar01 Project Calendar01Calendar02 Project Calendar02Calendarform01 Project Calendarform01Gallery01 Project Gallery01+4 | 4/8/2020 | 17/6/2026 | [Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] free edition ver1.0.0,… | |
| Modificada | Media (4.9) | 2.0% | — | Icegram Email Subscribers & Newsletters | 17/7/2020 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields. | |
| Modificada | Media (6.5) | 0.92% | — | Icegram Email Subscribers & Newsletters | 17/7/2020 | 17/6/2026 | Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link. | |
| Modificada | Alta (7.8) | 0.65% | — | Sourcefabric Newscoop | 19/5/2020 | 17/6/2026 | Because of Unrestricted Upload of a File with a Dangerous Type, Sourcefabric Newscoop 4.4.7 allows an authenticated user to execute arbitrary PHP code (and sometimes terminal commands) on a server by making an avatar update and then visiting the avatar file under the /images/ path. | |
| Modificada | Alta (8.8) | 2.1% | — | Cutephp Cutenews | 25/3/2020 | 17/6/2026 | CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. | |
| Modificada | Media (6.1) | 0.77% | — | Cutephp Cutenews | 25/3/2020 | 17/6/2026 | Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Alta (7.2) | 0.98% | — | Joobi Jnews | 9/3/2020 | 17/6/2026 | JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field. | |
| Modificada | Alta (8.8) | 1.1% | — | Joobi Jnews | 9/3/2020 | 17/6/2026 | JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension. | |
| Modificada | Crítica (9.8) | 1.4% | — | Magento Advanced Newsletter | 9/3/2020 | 17/6/2026 | SQL Injection exists in Advanced Newsletter Magento extension before 2.3.5 via the /store/advancednewsletter/index/subscribeajax/an_category_id/ PATH_INFO. | |
| Modificada | Media (4.8) | 0.54% | — | Joobi Jnews | 9/3/2020 | 17/6/2026 | JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter. |