Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.27% | — | Hide Email AddressAI | 12/12/2025 | 17/6/2026 | The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.21% | — | Webtoffee Decorator-woocommerce-email-customizerAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Winwar WP Email CaptureAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4. | |
| Aplazada | Media (4.3) | 0.29% | — | Elasticemail Elastic Email SenderAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elastic Email Sender: from n/a through <= 1.2.20. | |
| Aplazada | Alta (8.1) | 0.97% | — | SuremailAI | 2/12/2025 | 17/6/2026 | The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessible directory… | |
| Aplazada | Alta (7.2) | 0.30% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 2/12/2025 | 17/6/2026 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.2) | 0.44% | — | Icegram Email Subscribers AND NewslettersAI | 21/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10. | |
| Analizada | Media (5.3) | 0.33% | — | Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+1 | 20/11/2025 | 17/6/2026 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path. | |
| Analizada | Crítica (9.8) | 0.19% | — | Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+1 | 20/11/2025 | 17/6/2026 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution. | |
| Analizada | Media (5.4) | 0.20% | — | Email TFA Project Email TFA | 18/11/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6. | |
| Analizada | Baja (1.9) | 0.25% | — | Fabian Email Logging Interface | 15/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and could be used. | |
| Aplazada | Media (6.5) | 0.23% | — | Codepeople Contact Form TO EmailAI | 13/11/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.58. | |
| Aplazada | Alta (7.2) | 0.36% | — | Easy Email SubscriptionAI | 12/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (5.3) | 0.28% | — | Make Email Customizer FOR WoocommerceAI | 11/11/2025 | 17/6/2026 | The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options. | |
| Aplazada | Media (4.3) | 0.13% | — | Easy Email SubscriptionAI | 6/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a… | |
| Aplazada | Media (4.9) | 0.30% | — | Easy Email SubscriptionAI | 6/11/2025 | 17/6/2026 | The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,… | |
| Analizada | Baja (3.3) | 0.12% | — | Samsung Email | 5/11/2025 | 17/6/2026 | Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege. | |
| Aplazada | Media (5.9) | 0.18% | — | Villatheme Email Template Customizer FOR WoocommerceAI | 29/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce email-template-customizer-for-woo allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through <= 1.2.17. | |
| Aplazada | Media (4.3) | 0.30% | — | Reoon Technology Reoon Email VerifierAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Reoon Technology Reoon Email Verifier reoon-email-verifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reoon Email Verifier: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.5) | 0.20% | — | Siteground Email MarketingAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.1. | |
| Aplazada | Alta (8.8) | 0.47% | — | Iuliacazan Emails Catch ALLAI | 22/10/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.This issue affects Emails Catch All: from n/a through <= 3.5.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Weboccult Technologies PVT LTD Email Attachment BY Order Status ProductsAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status & Products: from n/a… | |
| Aplazada | Media (5.9) | 0.29% | — | I13websolution Email Subscription PopupAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nks Email Subscription Popup email-subscribe allows Stored XSS.This issue affects Email Subscription Popup: from n/a through <= 1.2.26. | |
| Aplazada | Media (4.9) | 0.37% | — | Email TrackerAI | 22/10/2025 | 17/6/2026 | The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Aplazada | Crítica (9.8) | 0.73% | — | Post BY EmailAI | 30/9/2025 | 17/6/2026 | The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function in all versions up to, and including, 1.0.4b. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make… |