Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2563▼ 389 respecto a la semana anterior
Críticas / altas1328▲ 46 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 468 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (3.1)0.28%—OnesignalAI16/4/202617/6/2026
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access…
AplazadaMedia (5.3)0.32%—OnesignalAI15/12/202517/6/2026
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due to the plugin processing POST requests without verifying user capabilities or…
ModificadaAlta (8.1)0.91%—React-native-onesignal27/3/202317/6/2026
OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on…
ModificadaMedia (5.4)1.1%—Onesignal-free-web-push-notifications30/8/201917/6/2026
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
ModificadaMedia (6.1)0.91%—Smokesignal Project Smokesignal21/8/201917/6/2026
The smokesignal plugin before 1.2.7 for WordPress has XSS.
ModificadaAlta (9.3)4.3%—Interactivedata Esignal16/9/201116/6/2026
Untrusted search path vulnerability in eSignal 10.6.2425.1208, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse JRS_UT.dll that is located in the same folder as a .quo (QUOTE) file. NOTE: the provenance of…
ModificadaAlta (10)56%—Interactivedata Esignal16/9/201116/6/2026
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (2) a long Font->FaceName field (aka FaceName element), which…
ModificadaAlta (7.5)6.7%—Esignal25/3/200416/6/2026
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.