Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.65% | — | Brevo Sendinblue FOR WoocommerceAI | 6/5/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to File System Calls.This issue affects Sendinblue for WooCommerce: from n/a through 4.0.17. | |
| Aplazada | Media (5.3) | 0.69% | — | Send PDF FOR Contact Form 7AI | 2/5/2024 | 17/6/2026 | The Send PDF for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of form submissions due to a missing capability check on the hooks function in all versions up to, and including, 1.0.2.3. This makes it possible for unauthenticated attackers to download information about contact form entries… | |
| Aplazada | Media (4.3) | 0.21% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend omnisend-connect.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through <= 1.14.3. | |
| Aplazada | Media (5.4) | 0.30% | — | Bogdanfix WP SendfoxAI | 11/4/2024 | 17/6/2026 | Missing Authorization vulnerability in BogdanFix WP SendFox.This issue affects WP SendFox: from n/a through 1.3.0. | |
| Analizada | Media (6.1) | 0.40% | — | Pressified Sendpress | 8/4/2024 | 17/6/2026 | The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Analizada | Media (6.8) | 0.71% | — | Pressified Sendpress | 8/4/2024 | 17/6/2026 | The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (5.9) | 0.36% | — | Aminur Islam WP Change Email SenderAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: from n/a before 1.3.0. | |
| Analizada | Alta (7.8) | 0.18% | — | Splashtop Mirroring360 ReceiverSplashtop Mirroring360 SenderSplashtopSplashtop FOR RMM+1 | 25/1/2024 | 17/6/2026 | The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using… | |
| Modificada | Media (5.3) | 0.43% | — | Sumanbhattarai Send Users Email | 5/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3. | |
| Modificada | Media (5.3) | 1.1% | — | SendmailFreebsdRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular… | |
| Modificada | Alta (7.5) | 0.55% | — | Omnisend Email Marketing FOR Woocommerce | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Omnisend Email Marketing for WooCommerce by Omnisend.This issue affects Email Marketing for WooCommerce by Omnisend: from n/a through 1.13.8. | |
| Modificada | Media (6.1) | 0.41% | — | Pressified Sendpress | 14/11/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.23.11.6 versions. | |
| Modificada | Media (4.1) | 1.1% | — | Microsoft Send Customer Voice Survey From Dynamics 365 | 14/11/2023 | 17/6/2026 | Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability | |
| Modificada | Media (5.4) | 0.66% | — | Pressified Sendpress | 7/11/2023 | 17/6/2026 | The SendPress Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.22.3.31 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.4) | 0.40% | — | Happybox Newsletter & Bulk Email Sender | 25/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in HappyBox Newsletter & Bulk Email Sender – Email Newsletter Plugin for WordPress plugin <= 2.0.1 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Joovii Sendle Shipping | 25/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Joovii Sendle Shipping Plugin plugin <= 5.13 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Sendpulse Free WEB Push | 16/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SendPulse SendPulse Free Web Push plugin <= 1.3.1 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Pressified Sendpress | 10/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Pressified Sendpress | 2/10/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SendPress Newsletters plugin <= 1.22.3.31 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Elasticemail Elastic Email Sender | 3/9/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Elastic Email Sender plugin <= 1.2.6 versions. | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Laserjet Managed MFP E62665 3gy14a FirmwareHP Laserjet Managed MFP E62665 3gy15a FirmwareHP Laserjet Managed MFP E62665 3gy16a FirmwareHP Laserjet Managed MFP E62665 3gy17a Firmware+953 | 14/6/2023 | 17/6/2026 | A potential security vulnerability has been identified for certain HP multifunction printers (MFPs). The vulnerability may lead to Buffer Overflow and/or Remote Code Execution when running HP Workpath solutions on potentially affected products. | |
| Modificada | Media (6.1) | 0.69% | — | Microsoft Send Customer Voice Survey From Dynamics 365 | 11/4/2023 | 17/6/2026 | Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | |
| Modificada | Alta (8.8) | 1.1% | — | Save Your Carts AND BUY Later OR Send IT Project Save Your Carts AND BUY Later OR Send IT | 10/4/2023 | 17/6/2026 | SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component. | |
| Modificada | Media (6.1) | 0.38% | — | Tussendoor Open RDW Kenteken Voertuiginformatie | 23/3/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in Tussendoor internet & marketing Open RDW kenteken voertuiginformatie plugin <= 2.0.14 versions. | |
| Modificada | Media (6.1) | 0.63% | — | Resend Welcome Email Project Resend Welcome Email | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading… |