Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2563▼ 389 respecto a la semana anterior
Críticas / altas1328▲ 46 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 468 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.1) | 0.28% | — | OnesignalAI | 16/4/2026 | 17/6/2026 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access… | |
| Aplazada | Media (5.3) | 0.32% | — | OnesignalAI | 15/12/2025 | 17/6/2026 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due to the plugin processing POST requests without verifying user capabilities or… | |
| Modificada | Alta (8.1) | 0.91% | — | React-native-onesignal | 27/3/2023 | 17/6/2026 | OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on… | |
| Modificada | Media (5.4) | 1.1% | — | Onesignal-free-web-push-notifications | 30/8/2019 | 17/6/2026 | The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter. | |
| Modificada | Media (6.1) | 0.91% | — | Smokesignal Project Smokesignal | 21/8/2019 | 17/6/2026 | The smokesignal plugin before 1.2.7 for WordPress has XSS. | |
| Modificada | Alta (9.3) | 4.3% | — | Interactivedata Esignal | 16/9/2011 | 16/6/2026 | Untrusted search path vulnerability in eSignal 10.6.2425.1208, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse JRS_UT.dll that is located in the same folder as a .quo (QUOTE) file. NOTE: the provenance of… | |
| Modificada | Alta (10) | 56% | — | Interactivedata Esignal | 16/9/2011 | 16/6/2026 | WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (2) a long Font->FaceName field (aka FaceName element), which… | |
| Modificada | Alta (7.5) | 6.7% | — | Esignal | 25/3/2004 | 16/6/2026 | Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag. |