Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.14% | — | Blacklist ManagerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. | |
| Aplazada | Media (5.4) | 0.17% | — | Blacklist Manager FOR WoocommerceAI | 28/9/2026 | 28/9/2026 | The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Thanhtungtnt Video List ManagerAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager video-list-manager allows SQL Injection.This issue affects Video List Manager: from n/a through <= 1.7. | |
| Aplazada | Alta (7.1) | 0.20% | — | Thanhtungtnt Video List ManagerAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thanhtungtnt Video List Manager video-list-manager allows Stored XSS.This issue affects Video List Manager: from n/a through <= 1.7. | |
| Aplazada | Alta (8.5) | 0.31% | — | Thanhtungtnt Video List ManagerAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video List Manager video-list-manager allows SQL Injection.This issue affects Video List Manager: from n/a through <= 1.7. | |
| Aplazada | Media (5.3) | 0.29% | — | Thanhtungtnt Video-list-managerAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in thanhtungtnt Video List Manager video-list-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Video List Manager: from n/a through <= 1.7. | |
| Aplazada | Media (5.4) | 0.36% | — | WEB Ready NOW WR Price List Manager FOR WoocommerceAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WR Price List Manager For Woocommerce: from n/a through <= 1.0.8. | |
| Aplazada | Crítica (9.9) | 0.51% | — | WEB Ready NOW WR Price List Manager FOR WoocommerceAI | 15/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-price-list-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects WR Price List Manager For Woocommerce: from n/a through <= 1.0.8. | |
| Modificada | Alta (7.2) | 3.2% | — | Video List Manager Project Video List Manager | 8/5/2023 | 17/6/2026 | The Video List Manager WordPress plugin through 1.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin | |
| Modificada | Media (6.1) | 0.76% | — | Link-list-manager Project Link-list-manager | 14/12/2021 | 17/6/2026 | The link-list-manager WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the category parameter found in the ~/llm.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0. | |
| Modificada | Crítica (9.8) | 2.1% | — | Mailing-manager Mailing List Manager PRO | 29/10/2017 | 17/6/2026 | Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template. | |
| Modificada | Media (4.3) | 1.9% | — | Lyris List Manager | 7/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in doemailpassword.tml in Lyris ListManager (LM) 8.95a allows remote attackers to inject arbitrary web script or HTML via the EmailAddr parameter. | |
| Modificada | Media (5) | 1.2% | — | Webinsta Mailing List Manager | 24/9/2011 | 16/6/2026 | WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files. | |
| Modificada | Media (5) | 2.8% | — | Ocean12 Technologies Mailing List Manager | 27/1/2009 | 16/6/2026 | Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb. | |
| Modificada | Media (4.3) | 1.7% | — | Ocean12 Technologies Mailing List Manager | 27/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Ocean12 Technologies Mailing List Manager | 27/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp. | |
| Modificada | Media (5) | 2.6% | — | Gazatem Technologies Qmail Mailing List Manager | 16/12/2008 | 16/6/2026 | Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb. | |
| Modificada | Media (4.3) | 1.3% | — | Lyris List Manager | 30/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to inject arbitrary web script or HTML via the words parameter. | |
| Modificada | Alta (10) | 2.6% | — | Lyris List Manager | 19/2/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain list administrator privileges or (2) access arbitrary mailing lists via unknown vectors related to modification of client-side information; and (3) allow remote… | |
| Modificada | Media (6.5) | 1.4% | — | Lyris List Manager | 6/9/2006 | 16/6/2026 | Lyris ListManager 8.95 allows remote authenticated users, who have administrative privileges for at least one list on the server, to add new administrators to any list via a modified MEMBERS_.List_ parameter. | |
| Modificada | Media (6.5) | 1.0% | — | Lyris List Manager | 6/9/2006 | 16/6/2026 | Lyris ListManager 8.95 allows remote authenticated users to obtain sensitive information by attempting to add a user with a ' (single quote) character in the name, which reveals the details of the underlying SQL query, possibly because of a forced SQL error or SQL injection. | |
| Modificada | Alta (7.5) | 3.5% | — | Webinsta Mailing List Manager | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter. | |
| Modificada | Baja (3.5) | 1.1% | — | Horde NAG Task List Manager H3 | 13/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in templates/tasklists/tasklists.inc in Horde Nag Task List Manager H3 before 2.0.4 allow remote authenticated users to inject arbitrary web script or HTML via (1) the tasklist's name or (2) description, when creating a new tasklist. | |
| Modificada | Alta (7.5) | 1.8% | — | Lyris List Manager | 10/12/2005 | 16/6/2026 | Lyris ListManager 5.0 through 8.9a allows remote attackers to add "ORDER BY" columns to SQL queries via unusual whitespace characters in the orderby parameter, such as (1) newlines and (2) 0xFF (ASCII 255) characters, which are interpreted as whitespace. | |
| Modificada | Alta (7.5) | 1.4% | — | Lyris List Manager | 10/12/2005 | 16/6/2026 | SQL injection vulnerability in Lyris ListManager 5.0 through 8.9a allows remote attackers to execute arbitrary SQL commands via SQL code after a numeric argument to a /read/attachment URL. |