Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | Europe Ecologie LES Verts Eelv NewsletterAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Europe Ecologie Les Verts EELV Newsletter eelv-newsletter allows Reflected XSS.This issue affects EELV Newsletter: from n/a through <= 4.8.2. | |
| Aplazada | Media (5.4) | 0.23% | — | Europe Ecologie LES Verts Eelv NewsletterAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Europe Ecologie Les Verts EELV Newsletter eelv-newsletter allows Cross Site Request Forgery.This issue affects EELV Newsletter: from n/a through <= 4.8.2. | |
| Modificada | Media (6.1) | 0.55% | — | Eelv Newsletter Project Eelv Newsletter | 4/6/2023 | 16/6/2026 | A vulnerability was found in EELV Newsletter Plugin 2.x on WordPress. It has been rated as problematic. Affected by this issue is the function style_newsletter of the file lettreinfo.php. The manipulation of the argument email leads to cross site scripting. The attack may be launched remotely. The name of the patch is… | |
| Modificada | Alta (8.8) | 0.67% | — | Eelv Newsletter Project Eelv Newsletter | 20/8/2019 | 17/6/2026 | The eelv-newsletter plugin before 4.6.1 for WordPress has CSRF in the address book. | |
| Modificada | Media (6.1) | 0.91% | — | Eelv Newsletter Project Eelv Newsletter | 20/8/2019 | 17/6/2026 | The eelv-newsletter plugin before 4.6.1 for WordPress has XSS in the address book. |