Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.6) | 0.29% | — | Email LOGAI | 23/9/2026 | 23/9/2026 | Administrator SQL Injection in Email Log <= 2.63 versions. | |
| Pendiente de análisis | Media (5.7) | 0.19% | — | Drupal Email Login OTPAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | |
| Analizada | Baja (1.9) | 0.25% | — | Fabian Email Logging Interface | 15/11/2025 | 17/6/2026 | A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and could be used. | |
| Aplazada | Media (6.5) | 0.68% | — | Postbox-email-logsAI | 13/12/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in wpdebuglog PostBox postbox-email-logs allows Retrieve Embedded Sensitive Data.This issue affects PostBox: from n/a through <= 1.0.4. | |
| Aplazada | Alta (8.1) | 0.82% | — | Email LOGAI | 24/5/2024 | 17/6/2026 | The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to… | |
| Modificada | Media (6.1) | 0.46% | — | Lanacodes Lana Email Logger | 12/7/2023 | 17/6/2026 | The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.83% | — | Email LOG Project Email LOG | 6/12/2021 | 17/6/2026 | The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 1.3% | — | Email LOG Project Email LOG | 17/11/2021 | 17/6/2026 | The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GET parameters before using them in SQL statement in the admin dashboard, leading to SQL injections |