Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.49% | — | Mailchimp Forms BY MailmunchAI | 5/8/2026 | 12/8/2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.1) | 0.36% | — | Soliton Systems Mailzen Management PortalAI | 4/8/2026 | 31/8/2026 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields. | |
| Aplazada | Alta (7.1) | 0.55% | — | SnailjobAI | 4/8/2026 | 24/9/2026 | SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload… | |
| Aplazada | Crítica (9.3) | 0.22% | — | BaileysAI | 3/8/2026 | 10/9/2026 | Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The… | |
| Aplazada | Baja (1.9) | 0.21% | — | Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI | 3/8/2026 | 12/8/2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with… | |
| Analizada | Alta (8.7) | 0.20% | — | Bouncycastle Bc-javaBouncycastle Bcjmail-fipsBouncycastle Bcmail-fipsBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X… | |
| Aplazada | Media (6.1) | 0.36% | — | WP Responsive Thumbnail SliderAI | 1/8/2026 | 12/8/2026 | The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']… | |
| Aplazada | Media (4.9) | 0.44% | — | Icegram MailerAI | 1/8/2026 | 12/8/2026 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs()… | |
| Aplazada | Alta (7.2) | 0.42% | — | Pluginops Mailchimp Subscribe FormAI | 1/8/2026 | 12/8/2026 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.4) | 0.35% | — | Sendpulse Email Marketing NewsletterAI | 1/8/2026 | 12/8/2026 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.39% | — | MailerpressAI | 31/7/2026 | 12/8/2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details. | |
| Aplazada | Media (5.3) | 0.39% | — | MailpressAI | 31/7/2026 | 12/8/2026 | The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback,… | |
| Aplazada | Media (6.5) | 0.27% | — | Mailgun FOR WordpressAI | 31/7/2026 | 26/8/2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's… | |
| Aplazada | Media (6.5) | 0.40% | — | Check LOG EmailAI | 31/7/2026 | 26/8/2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks. | |
| Pendiente de análisis | Crítica (9.5) | 2.1% | 💥 Exploit | Rails Action PackAILibvipsAIRubyonrails Active StorageAI | 30/7/2026 | 10/9/2026 | Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. | |
| Aplazada | Crítica (9.8) | 0.32% | — | Sourcecodester Tailor Management SystemAI | 30/7/2026 | 1/10/2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. | |
| Aplazada | Alta (7.1) | 0.55% | — | Courier ImapAICourier Mail ServerAI | 29/7/2026 | 30/7/2026 | Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with… | |
| Aplazada | Alta (7.1) | 0.13% | — | MailpoetAI | 23/7/2026 | 23/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | |
| Aplazada | Crítica (9.1) | 0.50% | — | MailsterAI | 23/7/2026 | 23/7/2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Retail Integration BUS | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful… | |
| Analizada | Crítica (9.8) | 0.51% | — | Oracle Retail Integration BUS | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful… | |
| Analizada | Alta (7.4) | 0.34% | — | Oracle Retail Eftlink | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink. Successful attacks of… | |
| Analizada | Media (4.3) | 0.27% | — | Oracle Retail Xstore Point OF Service | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of… | |
| Analizada | Baja (3.3) | 0.14% | — | Oracle Retail Xstore Point OF Service | 21/7/2026 | 7/8/2026 | Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service… |