Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
82 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (10) | 1.2% | — | Siemens Intermesh 7177 Hybrid 2.0 SubscriberSiemens Intermesh 7707 Fire Subscriber Firmware | 23/10/2024 | 17/6/2026 | A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The web server of affected devices does not sanitize the input parameters in… | |
| Analizada | Media (6.3) | 0.50% | — | Icegram Email Subscribers & Newsletters | 2/10/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to execute an action that does not properly… | |
| Analizada | Media (4.3) | 0.36% | — | Icegram Email Subscribers & Newsletters | 26/9/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it… | |
| Modificada | Media (4.3) | 0.38% | — | Icegram Email Subscribers & Newsletters | 17/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized API access due to a missing capability check in all versions up to, and including, 5.7.26. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 1.1% | — | Icegram Email Subscribers & Newsletters | 2/7/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of… | |
| Aplazada | Crítica (9.3) | 0.54% | — | Icegram Email Subscribers AND NewslettersAI | 26/6/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25. | |
| Modificada | Crítica (9.8) | 0.39% | — | Icegram Email Subscribers & Newsletters | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13. | |
| Modificada | Crítica (9.8) | 10% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 5/6/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.37% | — | Icegram Email SubscribersAI | 23/5/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content function in all versions up to, and including, 5.7.17. This makes it possible… | |
| Aplazada | Alta (8.8) | 0.39% | — | Icegram Email SubscribersAI | 15/5/2024 | 17/6/2026 | The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the handle_ajax_request function in all versions up to, and including, 5.7.19. This makes it possible for authenticated attackers, with… | |
| Aplazada | Crítica (9.8) | 81% | 💥 Exploit | Icegram Email SubscribersAI | 2/5/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'run' function of the 'IG_ES_Subscribers_Query' class in all versions up to, and including, 5.7.14 due to insufficient escaping on the user… | |
| Aplazada | Media (4.4) | 0.35% | — | Icegram Email SubscribersAI | 6/4/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a CSV import in all versions up to, and including, 5.7.14 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (7.1) | 0.39% | — | Icegram Email Subscribers AND NewslettersAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11. | |
| Modificada | Alta (7.5) | 0.67% | — | Gopiplus Email Posts TO Subscribers | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email posts to subscribers.This issue affects Email posts to subscribers: from n/a through 6.2. | |
| Modificada | Crítica (9.8) | 0.65% | — | Gopiplus Email Posts TO Subscribers | 3/11/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Gopi Ramasamy Email posts to subscribers allows SQL Injection.This issue affects Email posts to subscribers: from n/a through 6.2. | |
| Modificada | Media (4.8) | 0.36% | — | Gopiplus Email Posts TO Subscribers | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Email posts to subscribers plugin <= 6.2 versions. | |
| Modificada | Media (4.3) | 0.25% | — | Kreci Subscribers Text Counter | 30/8/2023 | 17/6/2026 | The Subscribers Text Counter WordPress plugin before 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack, which also lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping | |
| Modificada | Crítica (9.8) | 1.5% | — | Nvki Intelligent Broadband Subscriber Gateway | 21/8/2023 | 9/7/2026 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain an OS command injection vulnerability via shell metacharacters in the system_hostname parameter at /manage/network-basic.php. | |
| Modificada | Crítica (9.8) | 0.65% | — | Nvki Intelligent Broadband Subscriber Gateway | 21/8/2023 | 9/7/2026 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password that allows attackers to login with root privileges via the SSH service. The cleartext password corresponding to the $1$4Tmm01jl$7HRvcW.bz7uGmX9hiQWvR hash was not determined by the vulnerability discoverer. | |
| Modificada | Crítica (9.8) | 0.62% | — | Nvki Intelligent Broadband Subscriber Gateway | 21/8/2023 | 9/7/2026 | N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php. | |
| Modificada | Media (4.8) | 0.37% | — | Hellobar Subscribers | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Subscribers.Com Subscribers plugin <= 1.5.3 versions. | |
| Modificada | Alta (8.8) | 0.76% | — | Icegram Email Subscribers & Newsletters | 12/12/2022 | 17/6/2026 | The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber | |
| Modificada | Alta (7.8) | 0.26% | — | Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure | 6/4/2022 | 17/6/2026 | A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to insufficient access control in the affected CLI.… | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 7/3/2022 | 17/6/2026 | The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place… | |
| Modificada | Media (6.1) | 1.3% | — | Email-subscriber Project Email-subscriber | 23/8/2021 | 17/6/2026 | The kento_email_subscriber_ajax AJAX action of the Email Subscriber WordPress plugin through 1.1, does not properly sanitise, validate and escape the submitted subscribe_email and subscribe_name POST parameters, inserting them in the DB and then outputting them back in the Subscriber list… |