Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▼ 324 vs. last week
Critical / high1,284▼ 239 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (5.8) | 0.29% | — | Envialosimple Envialo SimpleAI | 4/18/2024 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvialoSimple EnvíaloSimple allows Reflected XSS.This issue affects EnvíaloSimple: from n/a through 2.2. | |
| Modified | High (8.8) | 0.41% | — | Donweb Envialosimple | 4/9/2024 | 6/17/2026 | The EnvíaloSimple: Email Marketing y Newsletters plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on the gallery_add function. This makes it possible for unauthenticated attackers to upload malicious files… | |
| Deferred | Medium (6.5) | 0.24% | — | EnvialosimpleAI | 3/26/2024 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in EnvialoSimple EnvíaloSimple.This issue affects EnvíaloSimple: from n/a through 2.2. | |
| Modified | Critical (9.8) | 0.56% | — | Donweb Envialosimple\ | 12/29/2023 | 6/17/2026 | Deserialization of Untrusted Data vulnerability in EnvialoSimple EnvíaloSimple: Email Marketing y Newsletters.This issue affects EnvíaloSimple: Email Marketing y Newsletters: from n/a through 2.1. | |
| Modified | Medium (4.3) | 1.6% | — | Envialosimple Email Marketing Y Newsletters | 7/2/2014 | 6/17/2026 | Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email-marketing-y-newsletters-gratis) plugin before 1.98 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) FormID or (2)… |