Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.52% | — | Silk Themes Newspapers XAI | 31/8/2026 | 1/9/2026 | Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48. | |
| Modificada | Alta (8.8) | 0.21% | — | Blazethemes Digital Newspaper | 21/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in blazethemes Digital Newspaper.This issue affects Digital Newspaper: from n/a through 1.1.5. | |
| Modificada | Media (4.8) | 0.28% | — | Tagdiv Newspaper | 15/6/2024 | 17/6/2026 | The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Alta (8.8) | 0.38% | — | Bdaia Woohoo Newspaper Magazine Theme | 20/11/2023 | 17/6/2026 | The WooHoo Newspaper Magazine theme does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.5) | 0.97% | — | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+11 | 7/6/2023 | 17/6/2026 | The Brilliance <= 1.2.7, Activello <= 1.4.0, and Newspaper X <= 1.3.1 themes for WordPress are vulnerable to Plugin Activation/Deactivation. This is due to the 'activello_activate_plugin' and 'activello_deactivate_plugin' functions in the 'inc/welcome-screen/class-activello-welcome.php' file missing capability and… | |
| Modificada | Crítica (9.8) | 65% | — | Colorlib ActivelloColorlib BonkersColorlib IlldyColorlib Newspaper X+12 | 7/6/2023 | 17/6/2026 | The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <=… | |
| Modificada | Crítica (9.8) | 3.0% | — | Newspaperclub PDF Info | 23/2/2023 | 17/6/2026 | pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3. | |
| Modificada | Crítica (9.8) | 3.8% | — | Newsmag Project NewsmagNewspaper Project NewspaperTagdiv Composer Project Tagdiv Composer | 14/11/2022 | 17/6/2026 | The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address | |
| Modificada | Media (6.1) | 1.0% | — | Tagdiv Newspaper | 31/10/2022 | 17/6/2026 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting. | |
| Modificada | Media (6.1) | 0.58% | — | Tagdiv Newspaper | 31/10/2022 | 17/6/2026 | The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.1) | 0.83% | — | Tagdiv Newspaper | 19/7/2021 | 17/6/2026 | An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax.php td_block_id parameter in a td_ajax_block API call. | |
| Modificada | Media (6.1) | 1.1% | — | Exquisite Ultimate Newspaper Project Exquisite Ultimate Newspaper | 22/10/2019 | 17/6/2026 | The Exquisite Ultimate Newspaper theme 1.3.3 for WordPress has XSS via the anchor identifier to assets/js/jquery.foundation.plugins.js. | |
| Modificada | Crítica (9.8) | 9.3% | — | Tagdiv Newspaper | 16/9/2019 | 17/6/2026 | The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel. | |
| Modificada | Crítica (9.8) | 2.2% | — | Tagdiv Newspaper | 16/9/2019 | 17/6/2026 | The newspaper theme before 6.7.2 for WordPress has script injection via td_ads[header] to admin-ajax.php. | |
| Modificada | Crítica (9.8) | 2.6% | — | Geniusocean Newspaper | 31/10/2017 | 17/6/2026 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | |
| Modificada | Media (5.4) | 0.27% | — | Independent I Newspaper | 19/10/2014 | 17/6/2026 | The i Newspaper (aka com.independent.thei) application @7F080184 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.42% | — | Alhazai Leadership Newspapers | 23/9/2014 | 17/6/2026 | The Leadership Newspapers (aka com.LeadershipNewspapers) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 1.6% | — | Emultisoft COM Jnewspaper | 19/5/2010 | 16/6/2026 | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 1.8% | — | Emultisoft COM Jnewspaper | 19/5/2010 | 16/6/2026 | SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. NOTE: some of these details are obtained from third party information. |