Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.70%—Snewscms Snews14/1/202016/6/2026
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
ModificadaMedia (5.3)2.5%—Md-systems Simplenews9/1/202016/6/2026
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
ModificadaCrítica (9.8)85%💥 ExploitIcegram Email Subscribers & Newsletters8/1/202017/6/2026
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
ModificadaAlta (7.4)0.52%—NTV News 2426/12/201917/6/2026
The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.3)71%💥 ExploitIcegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
ModificadaMedia (6.3)0.97%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
ModificadaMedia (5.3)1.2%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
ModificadaMedia (5.4)0.56%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
ModificadaMedia (4.3)1.0%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to…
ModificadaMedia (5.3)0.95%—Mailpoet Newsletters6/11/201917/6/2026
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
ModificadaMedia (6.1)0.93%—Weeklynews Theme Project Weeklynews Theme23/10/201917/6/2026
The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.
ModificadaMedia (6.1)1.1%—Exquisite Ultimate Newspaper Project Exquisite Ultimate Newspaper22/10/201917/6/2026
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
ModificadaAlta (8.8)2.2%—Freshmail-newsletter22/10/201917/6/2026
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
ModificadaMedia (6.1)0.94%—Momizat Goodnews20/9/201917/6/2026
The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.
ModificadaCrítica (9.8)9.3%💥 ExploitTagdiv Newspaper16/9/201917/6/2026
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
ModificadaCrítica (9.8)2.2%—Tagdiv Newspaper16/9/201917/6/2026
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
ModificadaCrítica (9.8)2.1%—Tribulant Newsletters22/8/201917/6/2026
The newsletters-lite plugin before 4.6.8.6 for WordPress has PHP object injection.
ModificadaCrítica (9.8)2.1%—Email-newsletter Project Email-newsletter22/8/201917/6/2026
The email-newsletter plugin through 20.15 for WordPress has SQL injection.
ModificadaMedia (6.1)0.92%—Newstatpress Project Newstatpress22/8/201917/6/2026
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
ModificadaAlta (8.8)0.67%—Eelv Newsletter Project Eelv Newsletter20/8/201917/6/2026
The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book.
ModificadaMedia (6.1)0.91%—Eelv Newsletter Project Eelv Newsletter20/8/201917/6/2026
The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book.
ModificadaAlta (8.8)3.7%—Tribulant Newsletters15/8/201917/6/2026
wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPress allows directory traversal with resultant remote PHP code execution via the subscribers[1][1] parameter in conjunction with an exportfile=../ value.
ModificadaAlta (8.8)0.65%—Newsletter BY Supsystic14/8/201917/6/2026
The newsletter-by-supsystic plugin before 1.1.8 for WordPress has CSRF.
ModificadaCrítica (9.8)1.8%—Newstatpress Project Newstatpress14/8/201917/6/2026
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
ModificadaMedia (6.1)0.92%—Newstatpress Project Newstatpress14/8/201917/6/2026
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
Orbitaley — Vulnerabilidades