Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.70% | — | Snewscms Snews | 14/1/2020 | 16/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71. | |
| Modificada | Media (5.3) | 2.5% | — | Md-systems Simplenews | 9/1/2020 | 16/6/2026 | The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page. | |
| Modificada | Crítica (9.8) | 85% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 8/1/2020 | 17/6/2026 | There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability). | |
| Modificada | Alta (7.4) | 0.52% | — | NTV News 24 | 26/12/2019 | 17/6/2026 | The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.3) | 71% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure. | |
| Modificada | Media (6.3) | 0.97% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns. | |
| Modificada | Media (5.3) | 1.2% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request. | |
| Modificada | Media (5.4) | 0.56% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings. | |
| Modificada | Media (4.3) | 1.0% | — | Icegram Email Subscribers & Newsletters | 26/12/2019 | 17/6/2026 | The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to… | |
| Modificada | Media (5.3) | 0.95% | — | Mailpoet Newsletters | 6/11/2019 | 17/6/2026 | An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks. | |
| Modificada | Media (6.1) | 0.93% | — | Weeklynews Theme Project Weeklynews Theme | 23/10/2019 | 17/6/2026 | The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter. | |
| Modificada | Media (6.1) | 1.1% | — | Exquisite Ultimate Newspaper Project Exquisite Ultimate Newspaper | 22/10/2019 | 17/6/2026 | The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js. | |
| Modificada | Alta (8.8) | 2.2% | — | Freshmail-newsletter | 22/10/2019 | 17/6/2026 | The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring. | |
| Modificada | Media (6.1) | 0.94% | — | Momizat Goodnews | 20/9/2019 | 17/6/2026 | The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter. | |
| Modificada | Crítica (9.8) | 9.3% | 💥 Exploit | Tagdiv Newspaper | 16/9/2019 | 17/6/2026 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | |
| Modificada | Crítica (9.8) | 2.2% | — | Tagdiv Newspaper | 16/9/2019 | 17/6/2026 | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | |
| Modificada | Crítica (9.8) | 2.1% | — | Tribulant Newsletters | 22/8/2019 | 17/6/2026 | The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection. | |
| Modificada | Crítica (9.8) | 2.1% | — | Email-newsletter Project Email-newsletter | 22/8/2019 | 17/6/2026 | The email-newsletter plugin through 20.15 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.92% | — | Newstatpress Project Newstatpress | 22/8/2019 | 17/6/2026 | The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues. | |
| Modificada | Alta (8.8) | 0.67% | — | Eelv Newsletter Project Eelv Newsletter | 20/8/2019 | 17/6/2026 | The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book. | |
| Modificada | Media (6.1) | 0.91% | — | Eelv Newsletter Project Eelv Newsletter | 20/8/2019 | 17/6/2026 | The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book. | |
| Modificada | Alta (8.8) | 3.7% | — | Tribulant Newsletters | 15/8/2019 | 17/6/2026 | wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value. | |
| Modificada | Alta (8.8) | 0.65% | — | Newsletter BY Supsystic | 14/8/2019 | 17/6/2026 | The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF. | |
| Modificada | Crítica (9.8) | 1.8% | — | Newstatpress Project Newstatpress | 14/8/2019 | 17/6/2026 | The newstatpress plugin before 1.0.1 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.92% | — | Newstatpress Project Newstatpress | 14/8/2019 | 17/6/2026 | The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. |