Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.27%—Hide Email AddressAI12/12/202517/6/2026
The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'inline_css' parameter in the `bg-hide-email-address` shortcode in all versions up to, and including, 0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…
AplazadaMedia (4.3)0.21%—Webtoffee Decorator-woocommerce-email-customizerAI9/12/202517/6/2026
Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1.
AplazadaMedia (5.3)0.25%—Winwar WP Email CaptureAI9/12/202517/6/2026
Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4.
AplazadaMedia (4.3)0.29%—Elasticemail Elastic Email SenderAI9/12/202517/6/2026
Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elastic Email Sender: from n/a through <= 1.2.20.
AplazadaAlta (8.1)0.97%—SuremailAI2/12/202517/6/2026
The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessible directory…
AplazadaAlta (7.2)0.30%—Kadencewp Kadence Woocommerce Email DesignerAI2/12/202517/6/2026
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in…
AplazadaAlta (7.2)0.44%—Icegram Email Subscribers AND NewslettersAI21/11/202517/6/2026
Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10.
AnalizadaMedia (5.3)0.33%—Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+120/11/202517/6/2026
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
AnalizadaCrítica (9.8)0.19%—Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+120/11/202517/6/2026
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
AnalizadaMedia (5.4)0.20%—Email TFA Project Email TFA18/11/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6.
AnalizadaBaja (1.9)0.25%—Fabian Email Logging Interface15/11/202517/6/2026
A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and could be used.
AplazadaMedia (6.5)0.23%—Codepeople Contact Form TO EmailAI13/11/202517/6/2026
Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.58.
AplazadaAlta (7.2)0.36%—Easy Email SubscriptionAI12/11/202517/6/2026
The Easy Email Subscription plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that…
AplazadaMedia (5.3)0.28%—Make Email Customizer FOR WoocommerceAI11/11/202517/6/2026
The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option validation in its AJAX actions, allowing any authenticated user, such as a Subscriber, to update arbitrary WordPress options.
AplazadaMedia (4.3)0.13%—Easy Email SubscriptionAI6/11/202517/6/2026
The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce validation on the show_editsub_page() function. This makes it possible for unauthenticated attackers to delete arbitrary subscribers via a…
AplazadaMedia (4.9)0.30%—Easy Email SubscriptionAI6/11/202517/6/2026
The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions up to, and including, 1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,…
AnalizadaBaja (3.3)0.12%—Samsung Email5/11/202517/6/2026
Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege.
AplazadaMedia (5.9)0.18%—Villatheme Email Template Customizer FOR WoocommerceAI29/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce email-template-customizer-for-woo allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through <= 1.2.17.
AplazadaMedia (4.3)0.30%—Reoon Technology Reoon Email VerifierAI27/10/202517/6/2026
Missing Authorization vulnerability in Reoon Technology Reoon Email Verifier reoon-email-verifier allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Reoon Email Verifier: from n/a through <= 2.0.1.
AplazadaMedia (6.5)0.20%—Siteground Email MarketingAI27/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.1.
AplazadaAlta (8.8)0.47%—Iuliacazan Emails Catch ALLAI22/10/202517/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iulia Cazan Emails Catch All emails-catch-all allows Password Recovery Exploitation.This issue affects Emails Catch All: from n/a through <= 3.5.3.
AplazadaAlta (7.1)0.25%—Weboccult Technologies PVT LTD Email Attachment BY Order Status ProductsAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weboccult Technologies Pvt Ltd Email Attachment by Order Status & Products email-attachment-by-order-status-products allows Reflected XSS.This issue affects Email Attachment by Order Status & Products: from n/a…
AplazadaMedia (5.9)0.29%—I13websolution Email Subscription PopupAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nks Email Subscription Popup email-subscribe allows Stored XSS.This issue affects Email Subscription Popup: from n/a through <= 1.2.26.
AplazadaMedia (4.9)0.37%—Email TrackerAI22/10/202517/6/2026
The Email Tracker – Email Log, Email Open Tracking, Email Analytics & Email Management for WordPress Emails plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 5.3.15 due to insufficient escaping on the user supplied parameter and lack of sufficient…
AplazadaCrítica (9.8)0.73%—Post BY EmailAI30/9/202517/6/2026
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the save_attachments function in all versions up to, and including, 1.0.4b. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make…