Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.29% | — | Phil88530 Simple Email SubscriberAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phil88530 Simple Email Subscriber simple-email-subscriber allows Reflected XSS.This issue affects Simple Email Subscriber: from n/a through <= 2.3. | |
| Aplazada | Alta (7.5) | 0.42% | — | Webbernaut Cloak Front END EmailAI | 17/4/2025 | 17/6/2026 | Missing Authorization vulnerability in webbernaut Cloak Front End Email allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Cloak Front End Email: from n/a through 1.9.5. | |
| Aplazada | Alta (7.1) | 0.29% | — | Debounce Email ValidatorAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows Reflected XSS.This issue affects DeBounce Email Validator: from n/a through <= 5.6.5. | |
| Aplazada | Crítica (9.1) | 0.61% | — | Stellarwp Kadence Woocommerce Email DesignerAI | 16/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-designer allows Upload a Web Shell to a Web Server.This issue affects Kadence WooCommerce Email Designer: from n/a through <= 1.5.14. | |
| Aplazada | Alta (7.5) | 0.47% | — | Notfound Macro Calculator With Admin Email Optin AND DataAI | 15/4/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NotFound Macro Calculator with Admin Email Optin & Data. This issue affects Macro Calculator with Admin Email Optin & Data: from n/a through 1.0. | |
| Aplazada | Alta (8.8) | 0.37% | — | Aweos Gmbh Email Notifications FOR UpdatesAI | 15/4/2025 | 17/6/2026 | Missing Authorization vulnerability in AWEOS GmbH Email Notifications for Updates wp-update-mail-notification allows Privilege Escalation.This issue affects Email Notifications for Updates: from n/a through <= 1.1.6. | |
| Aplazada | Alta (7.1) | 0.38% | — | Debounce Email ValidatorAI | 9/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows Stored XSS.This issue affects DeBounce Email Validator: from n/a through <= 5.7.1. | |
| Aplazada | Alta (8.8) | 0.39% | — | Email Notifications FOR UpdatesAI | 5/4/2025 | 17/6/2026 | The Email Notifications for Updates plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the awun_import_settings() function in all versions up to, and including, 1.1.6. This makes it possible for authenticated attackers,… | |
| Aplazada | Alta (7.5) | 0.72% | — | Debounce Email ValidatorAI | 3/4/2025 | 13/8/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in debounce DeBounce Email Validator debounce-io-email-validator allows PHP Local File Inclusion. This issue affects DeBounce Email Validator: from n/a through <= 5.7. | |
| Analizada | Alta (7.5) | 0.65% | — | Cisco Enterprise Chat AND Email | 2/4/2025 | 17/6/2026 | A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (8.8) | 0.56% | — | Email TFA Project Email TFA | 31/3/2025 | 17/6/2026 | Weak Authentication vulnerability in Drupal Email TFA allows Brute Force.This issue affects Email TFA: from 0.0.0 before 2.0.3. | |
| Aplazada | Alta (7.1) | 0.14% | — | Gagan Deep Singh Postmarkapp Email IntegratorAI | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Gagan Deep Singh PostmarkApp Email Integrator postmarkapp-email-integrator allows Cross Site Request Forgery.This issue affects PostmarkApp Email Integrator: from n/a through <= 2.4. | |
| Aplazada | Media (4.3) | 0.28% | — | Gagan Deep Singh Postmarkapp Email IntegratorAI | 31/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Gagan Deep Singh PostmarkApp Email Integrator postmarkapp-email-integrator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PostmarkApp Email Integrator: from n/a through <= 2.4. | |
| Aplazada | Media (5.3) | 0.37% | — | DAP TO Autoresponders Email SyncingAI | 29/3/2025 | 17/6/2026 | The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0 through the publicly accessible phpinfo.php script. This makes it possible for unauthenticated attackers to view potentially sensitive information contained in the… | |
| Aplazada | Media (4.3) | 0.21% | — | Publish Post Email NotificationAI | 27/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Nks publish post email notification publish-post-email-notification allows Cross Site Request Forgery.This issue affects publish post email notification: from n/a through <= 1.0.2.3. | |
| Aplazada | Media (5.9) | 0.35% | — | Clearoutio Clearout Email ValidatorAI | 27/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in clearoutio Clearout Email Validator clearout-email-validator allows Stored XSS.This issue affects Clearout Email Validator: from n/a through <= 3.2.0. | |
| Aplazada | Media (6.1) | 0.32% | — | SH Email AlertAI | 26/3/2025 | 17/6/2026 | The SH Email Alert plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mid' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Aplazada | Media (6.1) | 0.23% | — | Forcepoint Email SecurityAI | 24/3/2025 | 17/6/2026 | Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messages module) allows Stored XSS. This issue affects Email Security through 8.5.5. | |
| Aplazada | Media (5.4) | 0.18% | — | Speakpipe Voicemail FOR WebsitesAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SpeakPipe SpeakPipe speakpipe-voicemail-for-websites allows Cross Site Request Forgery.This issue affects SpeakPipe: from n/a through <= 0.2. | |
| Aplazada | Crítica (9.6) | 0.24% | — | Jacob Schwartz WP E Commerce Style EmailAI | 24/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Jacob Schwartz WP e-Commerce Style Email wp-e-commerce-style-email allows Code Injection.This issue affects WP e-Commerce Style Email: from n/a through <= 0.6.2. | |
| Analizada | Media (6.1) | 0.29% | — | Boopathirajan WP Test Email | 15/3/2025 | 17/6/2026 | The WP Test Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Email Logs in all versions up to, and including, 1.1.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Aplazada | Alta (7.1) | 0.15% | — | Philippe NO Disposable EmailAI | 11/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in philippe No Disposable Email no-disposable-email allows Stored XSS.This issue affects No Disposable Email: from n/a through <= 2.5.1. | |
| Modificada | Media (4.8) | 0.28% | — | Shanebp BP Email Assign Templates | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Stored XSS.This issue affects BP Email Assign Templates: from n/a through <= 1.6. | |
| Modificada | Media (4.9) | 0.45% | — | Shanebp BP Email Assign Templates | 11/3/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templates: from n/a through <= 1.7. | |
| Analizada | Media (5.4) | 0.16% | — | Intricateweb Email Keep | 8/3/2025 | 17/6/2026 | The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack |