Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
235 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 11/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (9) | 0.78% | — | Adobe Campaign | 11/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 11/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Aplazada | Alta (7.5) | 0.63% | — | WisecampaignAI | 5/8/2026 | 12/8/2026 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.87% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.8) | 0.95% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (10) | 0.95% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 1.0% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially… | |
| Analizada | Crítica (9.9) | 0.97% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.… | |
| Analizada | Crítica (10) | 1.4% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does… | |
| Analizada | Crítica (9.6) | 0.94% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.… | |
| Analizada | Crítica (9.8) | 1.2% | — | Adobe Campaign | 30/7/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (8.6) | 0.79% | — | Adobe Campaign | 30/7/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 30/6/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 9/6/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 0.95% | — | Adobe Campaign | 9/6/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia CampaigneventsAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch. | |
| Analizada | Crítica (9.3) | 0.23% | — | Teampass | 31/3/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicious JavaScript… | |
| Analizada | Crítica (9.3) | 0.27% | — | Teampass | 31/3/2026 | 17/6/2026 | Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in… | |
| Analizada | Media (6.1) | 0.16% | — | Hcltech UnicaHcltech Unica Audience CentralHcltech Unica CampaignHcltech Unica Centralised Offer Management+5 | 17/3/2026 | 17/6/2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in… | |
| Aplazada | Media (5.3) | 0.30% | — | Mailchimp CampaignsAI | 14/2/2026 | 17/6/2026 | The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the `mailchimp_campaigns_manager_disconnect_app` function that is hooked to the AJAX action of the same name. This makes it possible for… | |
| Analizada | Media (5.3) | 0.27% | — | Wikimedia Campaignevents | 9/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Media (4.3) | 0.22% | — | Campaignmonitor Campaign Monitor FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Campaign Monitor for WordPress: from n/a through 2.9.1. | |
| Analizada | Media (5.9) | 0.26% | — | Apache Streampark | 12/12/2025 | 17/6/2026 | When issuing JSON Web Tokens (JWT), Apache StreamPark directly uses the user's password as the HMAC signing key (e.g., with the HS256 algorithm). An attacker can exploit this vulnerability to perform offline brute-force attacks on the user's password using a captured JWT, or to arbitrarily forge identity tokens for… |