Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Mailing-manager Mailing List Manager PRO | 29/10/2017 | 17/6/2026 | Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template. | |
| Modificada | Media (6.1) | 1.4% | — | Epoch WEB Mailing List | 4/6/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Epoch Web Mailing List 0.31 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Webinsta Mailing List Manager | 24/9/2011 | 16/6/2026 | WEBinsta mailing list manager 1.3e allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/install3.php and certain other files. | |
| Modificada | Media (5) | 2.8% | — | Ocean12 Technologies Mailing List Manager | 27/1/2009 | 16/6/2026 | Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb. | |
| Modificada | Media (4.3) | 1.7% | — | Ocean12 Technologies Mailing List Manager | 27/1/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Ocean12 Technologies Mailing List Manager | 27/1/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp. | |
| Modificada | Media (5) | 2.6% | — | Gazatem Technologies Qmail Mailing List Manager | 16/12/2008 | 16/6/2026 | Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb. | |
| Modificada | Alta (7.5) | 3.5% | — | Webinsta Mailing List Manager | 17/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Techno Dreams Mailing List | 30/10/2005 | 16/6/2026 | SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp. | |
| Modificada | Alta (7.5) | 1.3% | — | Ocean12 Technologies Mailing List Manager | 3/5/2005 | 16/6/2026 | SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter. | |
| Modificada | Media (5) | 1.1% | — | Phplist Mailing List Manager | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Tincan Limited PHPlist before 2.8.12 has unknown impact and attack vectors, related to a "security update release." | |
| Modificada | Alta (7.5) | 6.2% | — | Eternalmart Mailing List Manager | 31/12/2003 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in EternalMart Mailing List Manager (EMLM) 1.32 allow remote attackers to execute arbitrary PHP code via a URL in (1) the emml_admin_path parameter to admin/auth.php or (2) the emml_path parameter to emml_email_func.php. |