Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.8% | — | Newstatpress Project Newstatpress | 14/8/2019 | 17/6/2026 | The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Newstatpress Project Newstatpress | 14/8/2019 | 17/6/2026 | The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element. | |
| Modificada | Media (6.1) | 0.92% | — | Newstatpress Project Newstatpress | 14/8/2019 | 17/6/2026 | The newstatpress plugin before 1.0.6 for WordPress has reflected XSS. | |
| Modificada | Media (5.4) | 1.0% | — | Tribulant Newsletters | 9/8/2019 | 17/6/2026 | The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newsletters_load_new_editor contentarea parameter. | |
| Modificada | Media (6.1) | 1.3% | — | Icegram Email Subscribers & Newsletters | 28/7/2019 | 17/6/2026 | An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject malicious JavaScript code through a publicly available subscription form using the esfpx_name wp-admin/admin-ajax.php POST parameter. | |
| Modificada | Crítica (9.8) | 3.7% | — | Icegram Email Subscribers & Newsletters | 19/7/2019 | 17/6/2026 | A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system. | |
| Modificada | Media (6.1) | 1.2% | — | Teclib-edition News | 10/7/2019 | 17/6/2026 | An issue was discovered in the Teclib News plugin through 1.5.2 for GLPI. It allows a stored XSS attack via the $_POST['name'] parameter. | |
| Modificada | Alta (8.8) | 52% | 💥 Exploit | Cutephp Cutenews | 22/4/2019 | 17/6/2026 | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.php?mod=main&opt=personal. There is no effective control of $imgsize in /core/modules/dashboard.php. The header content of a file can be… | |
| Modificada | Media (6.1) | 0.89% | — | Responsive Video News Script Project Responsive Video News Script | 16/2/2019 | 17/6/2026 | PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML injection or URL redirection. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id. | |
| Modificada | Media (4.8) | 2.6% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes | |
| Modificada | Media (4.8) | 3.1% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Media (4.8) | 2.9% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. | |
| Modificada | Alta (7.2) | 4.4% | 💥 Exploit | Kibokolabs Arigato Autoresponder AND Newsletter | 3/12/2018 | 17/6/2026 | There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request. | |
| Modificada | Crítica (9.8) | 4.2% | — | Kibokolabs Arigato Autoresponder AND Newsletter | 18/10/2018 | 17/6/2026 | The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachment.php. | |
| Modificada | Alta (7.5) | 1.4% | — | News-articles Project News-articles | 26/6/2018 | 17/6/2026 | ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.vb that can result in Attacker can read any file in the server or use smbrelay attack to access to server.. | |
| Modificada | Media (6.1) | 1.2% | — | Email Subscribers & Newsletters Project Email Subscribers & Newsletters | 26/6/2018 | 17/6/2026 | Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Chillcreations Ccnewsletter | 17/2/2018 | 17/6/2026 | SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099. | |
| Modificada | Crítica (9.8) | 1.7% | — | News Website Script Project News Website Script | 13/2/2018 | 17/6/2026 | PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term. | |
| Modificada | Alta (7.5) | 3.2% | — | Icegram Email Subscribers & Newsletters | 26/1/2018 | 17/6/2026 | An issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI with /?es=export at the end, and adding option=view_all_subscribers in the body, allows downloading of a CSV data file with all subscriber data. |