Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.23% | — | Sendpulse Email Marketing NewsletterAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Stored XSS.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.1.5. | |
| Aplazada | Alta (7.1) | 0.31% | — | Tosend.it PafacileAI | 3/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tosend.it PAFacile pafacile allows Reflected XSS.This issue affects PAFacile: from n/a through <= 2.6.1. | |
| Aplazada | Alta (7.1) | 0.17% | — | Braulio Aquino Send TO TwitterAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Braulio Aquino Send to Twitter send-to-twitter allows Stored XSS.This issue affects Send to Twitter: from n/a through <= 1.7.2. | |
| Aplazada | Media (4.3) | 0.41% | — | Smackcoders INC Sendgrid FOR WordpressAISendgrid FOR WordpressAI | 16/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Smackcoders Inc., SendGrid for WordPress wp-sendgrid-mailer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SendGrid for WordPress: from n/a through <= 1.4. | |
| Aplazada | Alta (7.1) | 0.26% | — | Catalinsendsms SendsmsAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in catalinsendsms SendSMS sendsms allows Reflected XSS.This issue affects SendSMS: from n/a through <= 1.2.9. | |
| Aplazada | Media (5.4) | 0.57% | — | Pechenki TelsenderAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Pechenki TelSender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TelSender: from n/a through 1.14.11. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Projectsend | 26/11/2024 | 14/7/2026 | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to options.php, enabling unauthorized modification of the application's configuration. Successful exploitation allows attackers to… | |
| Aplazada | Media (4.3) | 0.39% | — | Matt Miller Send Emails With MandrillAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Matt Miller Send Emails with Mandrill send-emails-with-mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through <= 1.4.1. | |
| Analizada | Media (4.3) | 0.36% | — | Smackcoders Sendgrid | 18/10/2024 | 17/6/2026 | The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_mailplus_clear_logs' function in all versions up to, and including, 1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete the… | |
| Aplazada | Media (5.3) | 0.36% | — | Bogdanfix WP SendfoxAI | 17/10/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in BogdanFix WP SendFox wp-sendfox allows Retrieve Embedded Sensitive Data.This issue affects WP SendFox: from n/a through <= 1.3.1. | |
| Aplazada | Alta (7.2) | 0.45% | — | Sendpulse Free WEB PushAI | 17/10/2024 | 17/6/2026 | The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.6 due to incorrect use of the wp_kses_allowed_html function. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a… | |
| Aplazada | Crítica (9.8) | 0.55% | — | FilesenderAI | 2/10/2024 | 17/6/2026 | FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials. | |
| Modificada | Media (4.7) | 0.54% | — | Send Project Send | 10/9/2024 | 17/6/2026 | Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0. | |
| Analizada | Crítica (9.8) | 2.0% | — | Smackcoders Sendgrid | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smackcoders SendGrid for WordPress allows SQL Injection.This issue affects SendGrid for WordPress: from n/a through 1.4. | |
| Analizada | Alta (8.8) | 0.21% | — | Sendinblue Newsletter, Smtp, Email Marketing AND Subscribe | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82. | |
| Analizada | Alta (8.8) | 0.20% | — | Sender | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through 2.6.18. | |
| Aplazada | Media (5.3) | 0.36% | — | Sumanbhattarai Send Users EmailAI | 13/8/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Send Users Email: from n/a through 1.5.1. | |
| Aplazada | Alta (7.1) | 0.30% | — | Sender Newsletter SMS AND Email Marketing Automation FOR WoocommerceAI | 12/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sender Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce allows Reflected XSS.This issue affects Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce: from n/a through… | |
| Analizada | Media (6.3) | 0.79% | — | Projectsend | 12/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the component Password Reset Token Handler. The manipulation leads to insufficiently random values. It is possible to launch the attack… | |
| Modificada | Media (6.9) | 0.79% | — | Projectsend | 12/8/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in projectsend up to r1605. This issue affects the function get_preview of the file process.php. The manipulation leads to improper control of resource identifiers. The attack may be initiated remotely. Upgrading to version r1720 is able to address… | |
| Analizada | Media (5.9) | 0.21% | — | Yasirwazir Send Email Only ON Reply TO MY Comment | 30/7/2024 | 17/6/2026 | The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack | |
| Analizada | Media (6.1) | 0.40% | — | Yasirwazir Send Email Only ON Reply TO MY Comment | 30/7/2024 | 17/6/2026 | The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Aplazada | Alta (7.4) | 0.25% | — | Toshiba PrintersAISendmailAI | 14/6/2024 | 17/6/2026 | Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the reference URL. | |
| Modificada | Crítica (9.8) | 0.42% | — | Pressified Sendpress | 14/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SendPress SendPress Newsletters.This issue affects SendPress Newsletters: from n/a through 1.23.11.6. | |
| Aplazada | Media (4.8) | 0.23% | — | Bwoodsend RockhopperAI | 27/5/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in bwoodsend rockhopper up to 0.1.2. Affected by this issue is the function count_rows of the file rockhopper/src/ragged_array.c of the component Binary Parser. The manipulation of the argument raw leads to buffer overflow. Local access is required to… |