Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

1110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.22%—Jegtheme Jnews Frontend SubmitAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews - Frontend Submit jnews-frontend-submit allows Reflected XSS.This issue affects JNews - Frontend Submit: from n/a through <= 11.0.0.
AplazadaCrítica (9.9)0.54%—Blazethemes News EventAI22/1/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in blazethemes News Event news-event.This issue affects News Event: from n/a through <= 1.0.1.
AplazadaMedia (4.3)0.12%—NewsletterAI20/1/202617/6/2026
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 9.1.0. This is due to missing or incorrect nonce validation on the hook_newsletter_action() function. This makes it possible for unauthenticated attackers to…
AnalizadaBaja (2.1)0.23%—Phpgurukul News Portal19/1/202617/6/2026
A security flaw has been discovered in PHPGurukul News Portal 1.0. The impacted element is an unknown function. Performing a manipulation results in cross-site request forgery. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
ModificadaBaja (2.1)0.34%—Phpgurukul News Portal19/1/202617/6/2026
A vulnerability was identified in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /admin/add-subadmins.php of the component Add Sub-Admin Page. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit is publicly available and might be used.
AplazadaCrítica (9.8)1.5%💥 PoCNews AND Blog Designer BundleAI14/1/202617/6/2026
The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1 via the template parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in…
AnalizadaCrítica (9.8)0.59%—Phpgurukul News Portal13/1/202617/6/2026
phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of any format to the server without identity authentication.
AnalizadaCrítica (9.8)0.46%—Phpgurukul News Portal13/1/202617/6/2026
phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
AnalizadaCrítica (9.1)0.45%—Phpgurukul News Portal13/1/202617/6/2026
phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file can cause any file to be deleted.
AplazadaCrítica (9.8)0.46%—Tribulant Software NewslettersAI8/1/20267/10/2026
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
AplazadaMedia (4.3)0.12%—Newsletter Email SubscribeAI7/1/20267/10/2026
The Newsletter Email Subscribe plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.4. This is due to incorrect nonce validation on the nels_settings_page function. This makes it possible for unauthenticated attackers to update plugin settings via a forged request…
AplazadaCrítica (9.9)0.51%—Themify SidepaneAIThemify NewsyAIThemify FoloAIThemify EdminAI+56/1/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themify Newsy, Themify Themify Folo, Themify Themify Edmin, Themify Bloggie, Themify Photobox, Themify Wigi, Themify Rezo, Themify Slide allows Upload a Web Shell to a Web Server.This issue affects…
AplazadaMedia (6.5)0.16%—Tribulant Software NewslettersAI30/12/20257/10/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Stored XSS.This issue affects Newsletters: from n/a through <= 4.12.
AnalizadaBaja (2)0.34%—Anirbandutta News-buzzCode-projects Content Management System29/12/20257/10/2026
A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has…
AplazadaAlta (8.1)0.50%—Pencidesign PennewsAI18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign PenNews pennews allows PHP Local File Inclusion.This issue affects PenNews: from n/a through < 6.7.3.
AplazadaAlta (7.6)0.40%—Stefano Lissa NewsletterAI16/12/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stefano Lissa Newsletter newsletter allows Blind SQL Injection.This issue affects Newsletter: from n/a through <= 9.0.9.
AplazadaMedia (4.3)0.26%—Sendpulse Email Marketing NewsletterAI16/12/202517/6/2026
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in SendPulse SendPulse Email Marketing Newsletter sendpulse-email-marketing-newsletter allows Retrieve Embedded Sensitive Data.This issue affects SendPulse Email Marketing Newsletter: from n/a through <= 2.2.1.
AnalizadaMedia (5.3)0.58%—Anirbandutta9 News-buzz15/12/202517/6/2026
SQL injection vulnerability in anirbandutta9 NEWS-BUZZ v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.
AplazadaMedia (6.4)0.23%—NewstatpressAI12/12/202517/6/2026
The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaMedia (4.3)0.12%—Jegtheme Jnews PaywallAI9/12/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in jegtheme JNews Paywall jnews-paywall allows Cross Site Request Forgery.This issue affects JNews Paywall: from n/a through < 12.0.1.
AplazadaMedia (5.3)0.25%—Pencidesign PennewsAI9/12/202517/6/2026
Missing Authorization vulnerability in PenciDesign PenNews pennews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PenNews: from n/a through < 6.7.4.
AplazadaMedia (6.5)0.20%—Jegtheme Jnews GalleryAI9/12/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jegtheme JNews Gallery jnews-gallery allows Stored XSS.This issue affects JNews Gallery: from n/a through < 12.0.1.
AplazadaMedia (6.5)0.25%—Jegstudio Gutenverse NewsAI9/12/202517/6/2026
Missing Authorization vulnerability in Jegstudio Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons gutenverse-news allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons: from n/a through <=…
AplazadaMedia (6.4)0.23%—Cute News TickerAI6/12/202517/6/2026
The Cute News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,…
AplazadaMedia (6.1)0.25%—Nouri.sh NewsletterAI5/12/202517/6/2026
The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` parameter in all versions up to, and including, 1.0.1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…