Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
1110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.44% | — | Icegram Email Subscribers AND NewslettersAI | 21/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10. | |
| Analizada | Baja (2) | 0.36% | — | Bdtask News365 | 14/11/2025 | 17/6/2026 | A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the file /admin/dashboard/profile. The manipulation of the argument profile_image/banner_image results in unrestricted upload. The attack can be launched remotely. The exploit has been released to the… | |
| Modificada | Baja (2.9) | 0.59% | — | Phpgurukul News Portal | 3/11/2025 | 17/6/2026 | A vulnerability was detected in PHPGurukul News Portal 1.0. The impacted element is an unknown function of the file /onps/settings.py. Performing a manipulation results in insertion of sensitive information into debugging code. It is possible to initiate the attack remotely. The attack's complexity is rated as high.… | |
| Analizada | Baja (1.3) | 0.42% | — | Phpgurukul News Portal | 3/11/2025 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul News Portal 1.0. The affected element is an unknown function of the file /onps/settings.py. Such manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . The attack may be performed from remote. The attack requires a high level of… | |
| Aplazada | Media (6.4) | 0.29% | — | JB News TickerAI | 22/10/2025 | 17/6/2026 | The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of the 'jbticker' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.25% | — | NewsupAI | 11/10/2025 | 17/6/2026 | The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the newsup_admin_info_install_plugin() function in all versions up to, and including, 5.0.10. This makes it possible for unauthenticated attackers to install the ansar-import plugin. | |
| Aplazada | Media (6.4) | 0.30% | — | ANY News TickerAI | 30/9/2025 | 17/6/2026 | The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shortcode in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.14% | — | NewsmanappAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NewsMAN NewsmanApp newsmanapp allows Stored XSS.This issue affects NewsmanApp: from n/a through <= 2.7.7. | |
| Analizada | Baja (1.9) | 0.28% | — | Transbyte Scooper News | 29/8/2025 | 17/6/2026 | A flaw has been found in Transbyte Scooper News App up to 1.2 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml of the component com.hatsune.eagleee. This manipulation causes improper export of android application components. The attack requires local access. The exploit… | |
| Aplazada | Alta (7.1) | 0.12% | — | Nonletter Newsletter Subscription Widget FOR SendblasterAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in nonletter Newsletter subscription optin module newsletter-subscription-widget-for-sendblaster allows Stored XSS.This issue affects Newsletter subscription optin module: from n/a through <= 1.2.9. | |
| Aplazada | Alta (7.1) | 0.12% | — | Google XML News SitemapAI | 28/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin gn-xml-sitemap allows Stored XSS.This issue affects Google XML News Sitemap plugin: from n/a through <= 0.02. | |
| Aplazada | Alta (7.1) | 0.11% | — | Geronikolov Instant Breaking NewsAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News instant-breaking-news allows Stored XSS.This issue affects Instant Breaking News: from n/a through <= 1.0. | |
| Aplazada | Alta (7.5) | 0.57% | — | Tribulant Software NewslettersAIPHPAI | 20/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Tribulant Software Newsletters newsletters-lite allows PHP Local File Inclusion.This issue affects Newsletters: from n/a through <= 4.10. | |
| Aplazada | Alta (7.5) | 0.56% | — | Wproyal News Magazine XAI | 14/8/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in wproyal News Magazine X news-magazine-x allows PHP Local File Inclusion.This issue affects News Magazine X: from n/a through <= 1.2.37. | |
| Aplazada | Baja (1.9) | 0.13% | — | Caixin News APPAI | 3/8/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Caixin News App 8.0.1 on Android. Affected is an unknown function of the file AndroidManifest.xml of the component com.caixin.news. The manipulation leads to improper export of android application components. Local access is required to approach this… | |
| Aplazada | Media (6.1) | 0.13% | — | YanewsflashAI | 23/7/2025 | 17/6/2026 | The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.3. This is due to missing or incorrect nonce validation on the 'yanewsflash/yanewsflash.php' page. This makes it possible for unauthenticated attackers to update settings and inject malicious web… | |
| Analizada | Baja (1.9) | 0.29% | — | Foresightnews Foresight News | 20/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Foresight News App up to 2.6.4 on Android. This vulnerability affects unknown code of the file AndroidManifest.xml of the component pro.foresightnews.appa. The manipulation leads to improper export of android application components. Attacking locally is a… | |
| Aplazada | Media (5.4) | 0.24% | — | Blazethemes News KIT Elementor AddonsAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.3.4. | |
| Aplazada | Media (4.3) | 0.14% | — | Tribulant Software NewslettersAI | 16/7/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Request Forgery.This issue affects Newsletters: from n/a through <= 4.10. | |
| Analizada | Media (5.4) | 0.25% | — | Jegstudio Gutenverse News | 19/6/2025 | 17/6/2026 | The Gutenverse News plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘elementId’ parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to… | |
| Modificada | Media (5.4) | 0.24% | — | Irmau IRM Newsroom | 13/6/2025 | 17/6/2026 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmcalendarview' shortcode in all versions up to, and including, 1.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.24% | — | Irmau IRM Newsroom | 13/6/2025 | 17/6/2026 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmflat' shortcode in all versions up to, and including, 1.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.4) | 0.24% | — | Irmau IRM Newsroom | 13/6/2025 | 17/6/2026 | The IRM Newsroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'irmeventlist' shortcode in all versions up to, and including, 1.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.28% | — | Sneeit FlatnewsAI | 9/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sneeit WordPress FlatNews Theme flatnews allows Reflected XSS.This issue affects WordPress FlatNews Theme: from n/a through <= 5.8. | |
| Analizada | Media (4.8) | 0.26% | — | Thenewsletterplugin Newsletter | 9/6/2025 | 17/6/2026 | The Newsletter WordPress plugin before 8.85 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). |