Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
116 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 11/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Aplazada | Alta (7.5) | 0.63% | — | WisecampaignAI | 5/8/2026 | 12/8/2026 | The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for… | |
| Analizada | Alta (7.5) | 0.87% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (9.8) | 0.95% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction. | |
| Analizada | Crítica (10) | 0.95% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 1.0% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary SQL commands, potentially… | |
| Analizada | Crítica (9.9) | 0.97% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.… | |
| Analizada | Crítica (10) | 1.4% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does… | |
| Analizada | Crítica (9.6) | 0.94% | — | Adobe Campaign | 3/8/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.… | |
| Analizada | Crítica (9.8) | 1.2% | — | Adobe Campaign | 30/7/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Alta (8.6) | 0.79% | — | Adobe Campaign | 30/7/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to gain file system read access. Exploitation of this issue does not require… | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 30/6/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Aplazada | Crítica (9.8) | 0.56% | 💥 PoC | Integration FOR Activecampaign AND Contact Form 7 Wpforms Elementor Ninja FormsAI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| Analizada | Crítica (10) | 1.2% | — | Adobe Campaign | 9/6/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Analizada | Crítica (10) | 0.95% | — | Adobe Campaign | 9/6/2026 | 28/8/2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed. | |
| Pendiente de análisis | Media (6.9) | 0.45% | — | Wikimedia MediawikiAIWikimedia CampaigneventsAI | 7/4/2026 | 21/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS). This issue was remediated only on the `master` branch. | |
| Analizada | Media (6.1) | 0.16% | — | Hcltech UnicaHcltech Unica Audience CentralHcltech Unica CampaignHcltech Unica Centralised Offer Management+5 | 17/3/2026 | 17/6/2026 | HTML Injection can be carried out in Product when a web application does not properly check or clean user input before showing it on a webpage. Because of this, an attacker may insert unwanted HTML code into the page. When the browser loads the page, it may automatically interact with external resources included in… | |
| Aplazada | Media (5.3) | 0.30% | — | Mailchimp CampaignsAI | 14/2/2026 | 17/6/2026 | The MailChimp Campaigns plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.2.4. This is due to missing capability checks on the `mailchimp_campaigns_manager_disconnect_app` function that is hooked to the AJAX action of the same name. This makes it possible for… | |
| Analizada | Media (5.3) | 0.27% | — | Wikimedia Campaignevents | 9/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Wikimedia Foundation MediaWiki - CampaignEvents extension allows Privilege Abuse.This issue affects MediaWiki - CampaignEvents extension: 1.45, 1.44, 1.43, 1.39. | |
| Aplazada | Media (4.3) | 0.22% | — | Campaignmonitor Campaign Monitor FOR WordpressAI | 8/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Campaign Monitor Campaign Monitor for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Campaign Monitor for WordPress: from n/a through 2.9.1. | |
| Aplazada | Media (4.3) | 0.18% | — | HCL Unica CampaignAI | 13/10/2025 | 17/6/2026 | HCL Unica Campaign 12.1.10 is vulnerable to Reflected Cross-Site Scripting (XSS) where an attacker injects malicious script into an HTTP request, which is then reflected unsafely in the server's immediate response to the victim's browser, executing the script as if it originated from the trusted website. | |
| Analizada | Media (5.6) | 0.25% | — | JLY Campaignevents | 3/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: from 1.43.X before 1.43.2. | |
| Aplazada | Media (5.9) | 0.41% | — | Activecampaign-subscription-formsAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in activecampaign ActiveCampaign activecampaign-subscription-forms allows Stored XSS.This issue affects ActiveCampaign: from n/a through <= 8.1.16. | |
| Analizada | Media (6.9) | 0.62% | — | 1000projects Campaign Management System Platform FOR Women | 17/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Code/loginnew.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The… | |
| Analizada | Media (6.9) | 0.62% | — | 1000projects Campaign Management System Platform FOR Women | 17/1/2025 | 17/6/2026 | A vulnerability was found in 1000 Projects Campaign Management System Platform for Women 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Code/sc_login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely.… |