Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.24% | — | SendyAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in sendy Sendy sendy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendy: from n/a through <= 3.4.2. | |
| Aplazada | Alta (8.4) | 0.53% | — | LansendAI | 3/2/2026 | 17/6/2026 | LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute shellcode when importing computers from a… | |
| Analizada | Media (6.1) | 0.32% | — | Localsend | 30/1/2026 | 17/6/2026 | LocalSend is a free, open-source app that allows users to share files and messages with nearby devices over their local network without needing an internet connection. In versions up to and including 1.17.0, when a user initiates a "Share via Link" session, the LocalSend application starts a local HTTP server to host… | |
| Aplazada | Media (5.3) | 0.33% | — | Moosend Landing PagesAI | 7/1/2026 | 17/6/2026 | The Moosend Landing Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the moosend_landings_auth_get function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Analizada | Alta (8.7) | 0.95% | — | Projectsend | 22/12/2025 | 17/6/2026 | ProjectSend r1605 contains a remote code execution vulnerability that allows attackers to upload malicious files by manipulating file extensions. Attackers can upload shell scripts with disguised extensions through the upload.process.php endpoint to execute arbitrary commands on the server. | |
| Modificada | Alta (7.1) | 0.38% | — | Projectsend | 17/12/2025 | 17/6/2026 | ProjectSend r1605 contains an insecure direct object reference vulnerability that allows unauthenticated attackers to download private files by manipulating the download ID parameter. Attackers can access any user's private files by changing the 'id' parameter in the download request to process.php. | |
| Modificada | Media (5.1) | 0.31% | — | Projectsend | 17/12/2025 | 17/6/2026 | projectSend r1605 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript through the custom assets configuration page. Attackers can craft a JavaScript payload in the custom assets section that will execute when other users load the affected page,… | |
| Modificada | Media (6.2) | 0.50% | — | Projectsend | 17/12/2025 | 17/6/2026 | ProjectSend r1605 contains a CSV injection vulnerability that allows authenticated users to inject malicious formulas into user profile names. Attackers can craft payloads like =calc|a!z| in the name field to trigger code execution when administrators export action logs as CSV files. | |
| Aplazada | Media (4.3) | 0.26% | — | Sendpulse Email Marketing NewsletterAI | 16/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Retrieve Embedded Sensitive Data.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.2.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Brevo Sendinblue FOR WoocommerceAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Brevo Sendinblue for WooCommerce woocommerce-sendinblue-newsletter-subscription allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sendinblue for WooCommerce: from n/a through <= 4.0.49. | |
| Aplazada | Media (4.3) | 0.29% | — | Elasticemail Elastic Email SenderAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elastic Email Sender: from n/a through <= 1.2.20. | |
| Aplazada | Baja (2) | 0.25% | — | ProjectsendAI | 16/11/2025 | 17/6/2026 | A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may be used. Upgrading to version r1945 is… | |
| Aplazada | Media (5.3) | 0.28% | — | Joovii Sendle ShippingAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Sendle Shipping: from n/a through <= 6.02. | |
| Aplazada | Media (4.3) | 0.25% | — | Clicksend SMS Contact Form 7 NotificationsAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in clicksend SMS Contact Form 7 Notifications by ClickSend clicksend-contactform7 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SMS Contact Form 7 Notifications by ClickSend: from n/a through <= 1.4.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Joovii Sendle ShippingAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Cross Site Request Forgery.This issue affects Sendle Shipping: from n/a through <= 6.02. | |
| Aplazada | Media (4.7) | 0.23% | — | Pusula Communication Information Manageable Email Sending SystemAI | 19/9/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Pusula Communication Information Internet Industry and Trade Ltd. Co. Manageable Email Sending System allows Exploiting Trust in Client. This issue affects Manageable Email Sending System: from <=2025.06 before 2025.08.06. | |
| Aplazada | Alta (7.1) | 0.12% | — | Nonletter Newsletter Subscription Widget FOR SendblasterAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module newsletter-subscription-widget-for-sendblaster allows Stored XSS.This issue affects Newsletter subscription optin module: from n/a through <= 1.2.9. | |
| Analizada | Crítica (9.3) | 0.27% | — | Localsend | 1/8/2025 | 17/6/2026 | LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection. In versions 1.16.1 and below, a critical Man-in-the-Middle (MitM) vulnerability in the software's discovery protocol allows an unauthenticated attacker on the same local… | |
| Aplazada | Alta (7.6) | 0.39% | — | Yaycommerce Smtp FOR Sendgrid YaysmtpAI | 16/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP for SendGrid – YaySMTP smtp-sendgrid allows SQL Injection.This issue affects SMTP for SendGrid – YaySMTP: from n/a through <= 1.5. | |
| Modificada | Media (5.4) | 0.26% | — | Sendpulse Email Marketing Newsletter | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.1.6. | |
| Aplazada | Media (5.9) | 0.27% | — | Benjamin Buddle Send FromAI | 24/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Benjamin Buddle Send From send-from allows Stored XSS.This issue affects Send From: from n/a through <= 2.2. | |
| Aplazada | Media (6.5) | 0.26% | — | Paolo Melchiorre Send E-mailAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paolo Melchiorre Send E-mail send-e-mail allows Stored XSS.This issue affects Send E-mail: from n/a through <= 1.3. | |
| Aplazada | Media (5.3) | 0.29% | — | Sendquick EnteraAI | 14/3/2025 | 17/6/2026 | SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass by removing the Captcha parameter. | |
| Aplazada | Alta (7.1) | 0.37% | — | Pinal.shah Send-booking-invites-to-friendsAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pinal.shah Send to a Friend Addon send-booking-invites-to-friends allows Reflected XSS.This issue affects Send to a Friend Addon: from n/a through <= 1.4.1. | |
| Analizada | Media (6.3) | 0.54% | — | Localsend | 25/2/2025 | 17/6/2026 | LocalSend is a free, open-source app that allows users to securely share files and messages with nearby devices over their local network without needing an internet connection. Prior to version 1.17.0, due to the missing sanitization of the path in the `POST /api/localsend/v2/prepare-upload` and the `POST… |