Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

4598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.49%—Mailchimp Forms BY MailmunchAI5/8/202612/8/2026
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and…
AplazadaMedia (6.1)0.36%—Soliton Systems Mailzen Management PortalAI4/8/202631/8/2026
Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields.
AplazadaAlta (7.1)0.55%—SnailjobAI4/8/202624/9/2026
SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can store a base64-encoded Zstandard payload…
AplazadaCrítica (9.3)0.22%—BaileysAI3/8/202610/9/2026
Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This allows anyone to spoof messages. The…
AplazadaBaja (1.9)0.21%—Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI3/8/202612/8/2026
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with…
AnalizadaAlta (8.7)0.20%—Bouncycastle Bc-javaBouncycastle Bcjmail-fipsBouncycastle Bcmail-fipsBouncycastle Bouncy Castle FOR Java LTS3/8/202628/8/2026
In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X…
AplazadaMedia (6.1)0.36%—WP Responsive Thumbnail SliderAI1/8/202612/8/2026
The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and excluding, 1.1.53. This is due to insufficient input sanitization and output escaping in the responsive_thumbnail_image_management() function, which echoes $_GET['id']…
AplazadaMedia (4.9)0.44%—Icegram MailerAI1/8/202612/8/2026
The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs()…
AplazadaAlta (7.2)0.42%—Pluginops Mailchimp Subscribe FormAI1/8/202612/8/2026
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
AplazadaMedia (6.4)0.35%—Sendpulse Email Marketing NewsletterAI1/8/202612/8/2026
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (5.3)0.39%—MailerpressAI31/7/202612/8/2026
The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details.
AplazadaMedia (5.3)0.39%—MailpressAI31/7/202612/8/2026
The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback,…
AplazadaMedia (6.5)0.27%—Mailgun FOR WordpressAI31/7/202626/8/2026
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's…
AplazadaMedia (6.5)0.40%—Check LOG EmailAI31/7/202626/8/2026
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks.
Pendiente de análisisCrítica (9.5)2.1%💥 ExploitRails Action PackAILibvipsAIRubyonrails Active StorageAI30/7/202610/9/2026
Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured…
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
AplazadaCrítica (9.8)0.32%—Sourcecodester Tailor Management SystemAI30/7/20261/10/2026
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
AplazadaAlta (7.1)0.55%—Courier ImapAICourier Mail ServerAI29/7/202630/7/2026
Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with…
AplazadaAlta (7.1)0.13%—MailpoetAI23/7/202623/7/2026
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
AplazadaCrítica (9.1)0.50%—MailsterAI23/7/202623/7/2026
Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.
AnalizadaCrítica (9.8)0.51%—Oracle Retail Integration BUS21/7/202631/7/2026
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 16.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful…
AnalizadaCrítica (9.8)0.51%—Oracle Retail Integration BUS21/7/202631/7/2026
Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal). The supported version that is affected is 14.1.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus. Successful…
AnalizadaAlta (7.4)0.34%—Oracle Retail Eftlink21/7/20267/8/2026
Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported versions that are affected are 21.0.0-25.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail EFTLink. Successful attacks of…
AnalizadaMedia (4.3)0.27%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Xstore Point of…
AnalizadaBaja (3.3)0.14%—Oracle Retail Xstore Point OF Service21/7/20267/8/2026
Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Xstore Point of Service…