Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

90 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.1%—Icegram Email Subscribers & Newsletters2/7/202417/6/2026
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied parameter and lack of…
AplazadaCrítica (9.3)0.54%—Icegram Email Subscribers AND NewslettersAI26/6/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.25.
ModificadaAlta (8.8)0.23%—Tribulant Newsletters21/6/202417/6/2026
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7.
ModificadaCrítica (9.8)0.39%—Icegram Email Subscribers & Newsletters9/6/202417/6/2026
Missing Authorization vulnerability in Email Subscribers & Newsletters.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.13.
ModificadaMedia (6.1)0.29%—Tribulant Newsletters8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tribulant Newsletters allows Reflected XSS.This issue affects Newsletters: from n/a through 4.9.5.
ModificadaCrítica (9.8)10%💥 ExploitIcegram Email Subscribers & Newsletters5/6/202417/6/2026
The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in all versions up to, and including, 5.7.20 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for…
AplazadaCrítica (9.1)0.60%—Tribulant NewslettersAI24/4/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
AplazadaAlta (7.5)0.68%—NewslettersAI24/4/202417/6/2026
Insertion of Sensitive Information into Log File vulnerability in Newsletters.This issue affects Newsletters: from n/a through 4.9.5.
AplazadaAlta (7.1)0.39%—Icegram Email Subscribers AND NewslettersAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Icegram Email Subscribers & Newsletters allows Reflected XSS.This issue affects Email Subscribers & Newsletters: from n/a through 5.7.11.
ModificadaAlta (7.2)0.96%—Tribulant Newsletters16/1/202417/6/2026
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
ModificadaAlta (8.8)0.30%—Tribulant Newsletters10/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters plugin <= 4.8.8 versions.
ModificadaAlta (8.8)0.76%—Icegram Email Subscribers & Newsletters12/12/202217/6/2026
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
ModificadaAlta (8.8)4.2%💥 ExploitIcegram Email Subscribers & Newsletters7/3/202217/6/2026
The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place…
ModificadaAlta (8.8)0.70%—Sola-newsletters Project Sola-newsletters5/8/202117/6/2026
The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function found in the ~/sola-newsletters.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.23.
ModificadaMedia (6.1)0.75%—Ec-cube Email Newsletters Management22/6/202117/6/2026
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.
ModificadaMedia (5.3)1.6%—Icegram Email Subscribers & Newsletters10/9/202017/6/2026
Missing Authentication for Critical Function in Icegram Email Subscribers & Newsletters Plugin for WordPress prior to version 4.5.6 allows a remote, unauthenticated attacker to conduct unauthenticated email forgery/spoofing.
ModificadaMedia (4.9)2.0%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote, authenticated attacker to determine the value of database fields.
ModificadaMedia (6.5)0.92%—Icegram Email Subscribers & Newsletters17/7/202017/6/2026
Cross-site request forgery in Icegram Email Subscribers & Newsletters Plugin for WordPress v4.4.8 allows a remote attacker to send forged emails by tricking legitimate users into clicking a crafted link.
ModificadaCrítica (9.8)85%💥 ExploitIcegram Email Subscribers & Newsletters8/1/202017/6/2026
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to be passed to the database in the hash parameter (a blind SQL injection vulnerability).
ModificadaMedia (5.3)71%💥 ExploitIcegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file download with user information disclosure.
ModificadaMedia (6.3)0.97%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed users with edit_post capabilities to manage plugin settings and email campaigns.
ModificadaMedia (5.3)1.2%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for unauthenticated option creation. In order to exploit this vulnerability, an attacker would need to send a /wp-admin/admin-post.php?es_skip=1&option_name= request.
ModificadaMedia (5.4)0.56%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed for CSRF to be exploited on all plugin settings.
ModificadaMedia (4.3)1.0%—Icegram Email Subscribers & Newsletters26/12/201917/6/2026
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a privilege bypass flaw that allowed authenticated users (Subscriber or greater access) to send test emails from the administrative dashboard on behalf of an administrator. This occurs because the plugin registers a wp_ajax function to…
ModificadaMedia (5.3)0.95%—Mailpoet Newsletters6/11/201917/6/2026
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
Orbitaley — Vulnerabilidades