Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.26% | — | Cleantalk Anti-spam | 10/7/2026 | 6/8/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Oopspam Anti-spamAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OOPSpam Team OOPSpam Anti-Spam oopspam-anti-spam allows Stored XSS.This issue affects OOPSpam Anti-Spam: from n/a through <= 1.2.62. | |
| Analizada | Media (4.7) | 0.21% | — | Cleantalk Anti-spam | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Cross-Site Scripting (XSS).This issue affects Anti-Spam by CleanTalk: from 0.0.0 before 9.7.0. | |
| Aplazada | Alta (7.1) | 0.13% | — | Nixsolutions NIX Anti-spam LightAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Cross Site Request Forgery.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4. | |
| Analizada | Alta (7.5) | 15% | 💥 PoC | Cleantalk Anti-spam | 26/11/2024 | 17/6/2026 | The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated… | |
| Modificada | Crítica (9.8) | 0.52% | — | Nixsolutions NIX Anti-spam Light | 18/11/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= 0.0.4. | |
| Aplazada | Media (6.5) | 0.49% | — | Creativemotion Titan Anti-spam SecurityAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6. | |
| Modificada | Alta (8.8) | 0.24% | — | Cleantalk Anti-spam | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20. | |
| Modificada | Media (6.1) | 0.44% | — | Peterkeung Peter's Custom Anti-spam | 25/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Peter Keung Peter’s Custom Anti-Spam plugin <= 3.2.2 versions. | |
| Modificada | Media (6.1) | 0.48% | — | WP Cerber Security, Anti-spam & Malware Scan | 20/10/2023 | 17/6/2026 | The WP Cerber Security plugin for WordPress is vulnerable to stored cross-site scripting via the log parameter when logging in to the site in versions up to, and including, 9.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an… | |
| Modificada | Alta (8.8) | 0.27% | — | Oopspam Anti-spam | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.44 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Oopspam Anti-spam | 23/3/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.35 versions. | |
| Modificada | Media (5.3) | 0.67% | — | WP Cerber Security, Anti-spam & Malware Scan | 2/1/2023 | 17/6/2026 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 9.3.3 does not properly block access to the REST API users endpoint when the blog is in a subdirectory, which could allow attackers to bypass the restriction in place and list users | |
| Modificada | Media (5.3) | 0.76% | — | Cm-wp Titan Anti-spam & Security | 16/9/2022 | 17/6/2026 | The Titan Anti-spam & Security WordPress plugin before 7.3.1 does not properly checks HTTP headers in order to validate the origin IP address, allowing threat actors to bypass it's block feature by spoofing the headers. | |
| Modificada | Media (5.3) | 0.86% | — | WP Cerber Security, Anti-spam & Malware Scan | 6/9/2022 | 17/6/2026 | The WP Cerber Security plugin for WordPress is vulnerable to security protection bypass in versions up to, and including 9.0, that makes user enumeration possible. This is due to improper validation on the value supplied through the 'author' parameter found in the ~/cerber-load.php file. In vulnerable versions, the… | |
| Modificada | Media (6.1) | 0.65% | — | Wp-spamfree Anti-spam Project Wp-spamfree Anti-spam | 24/6/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknown part. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely. | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | WP Cerber Security, Anti-spam & Malware Scan | 7/3/2022 | 17/6/2026 | The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability. | |
| Modificada | Alta (7.2) | 1.4% | — | Cleantalk Anti-spam | 18/3/2021 | 17/6/2026 | Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+). | |
| Modificada | Alta (7.8) | 0.77% | — | Anti-spam Smtp Proxy Project Anti-spam Smtp Proxy | 8/11/2017 | 17/6/2026 | The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script. | |
| Modificada | Media (4.3) | 2.0% | — | SI Captcha Anti-spam Project SI Captcha Anti-spam | 7/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in captcha-secureimage/test/index.php in the SI CAPTCHA Anti-Spam plugin 2.7.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | |
| Modificada | Media (4.3) | 5.8% | 💥 Exploit | Peter's Math Anti-spam FOR Wordpress | 11/9/2009 | 16/6/2026 | Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip. | |
| Modificada | Media (4.3) | 1.1% | — | Commtouch Enterprise Anti-spam Gateway | 9/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in UPM/English/login/login.asp in Commtouch Enterprise Anti-Spam Gateway 4 and 5 allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Peters Software Random Anti-spam Image | 10/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form. | |
| Modificada | Alta (7.5) | 1.4% | — | Anti-spam Smtp Proxy Server | 10/8/2007 | 16/6/2026 | Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors. | |
| Modificada | Media (4.4) | 0.28% | — | Kaspersky LAB Kaspersky Anti-spam | 8/8/2007 | 16/6/2026 | Kaspersky Anti-Spam 3.0 MP1 before Critical Fix 2 (3.0.278.4) sets incorrect permissions for application files in certain upgrade scenarios, which might allow local users to gain privileges. |