Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (10)0.52%—Silk Themes Newspapers XAI31/8/20261/9/2026
Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.
ModificadaAlta (8.8)0.21%—Blazethemes Digital Newspaper21/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5.
ModificadaMedia (4.8)0.28%—Tagdiv Newspaper15/6/202417/6/2026
The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaAlta (8.8)0.38%—Bdaia Woohoo Newspaper Magazine Theme20/11/202317/6/2026
The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.5)0.97%—Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+117/6/202317/6/2026
The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and…
ModificadaCrítica (9.8)65%—Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+127/6/202317/6/2026
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=…
ModificadaCrítica (9.8)3.0%—Newspaperclub PDF Info23/2/202317/6/2026
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
ModificadaCrítica (9.8)3.8%—Newsmag Project NewsmagNewspaper Project NewspaperTagdiv Composer Project Tagdiv Composer14/11/202217/6/2026
The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address
ModificadaMedia (6.1)1.0%—Tagdiv Newspaper31/10/202217/6/2026
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting.
ModificadaMedia (6.1)0.58%—Tagdiv Newspaper31/10/202217/6/2026
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
ModificadaMedia (6.1)0.83%—Tagdiv Newspaper19/7/202117/6/2026
An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call.
ModificadaMedia (6.1)1.1%—Exquisite Ultimate Newspaper Project Exquisite Ultimate Newspaper22/10/201917/6/2026
The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js.
ModificadaCrítica (9.8)9.3%—Tagdiv Newspaper16/9/201917/6/2026
The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
ModificadaCrítica (9.8)2.2%—Tagdiv Newspaper16/9/201917/6/2026
The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php.
ModificadaCrítica (9.8)2.6%—Geniusocean Newspaper31/10/201717/6/2026
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
ModificadaMedia (5.4)0.27%—Independent I Newspaper19/10/201417/6/2026
The i Newspaper (aka com.independent.thei) application @7F080184 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.42%—Alhazai Leadership Newspapers23/9/201417/6/2026
The Leadership Newspapers (aka com.LeadershipNewspapers) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (6.8)1.6%—Emultisoft COM Jnewspaper19/5/201016/6/2026
SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaAlta (7.5)1.8%—Emultisoft COM Jnewspaper19/5/201016/6/2026
SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information.