Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.42% | — | MailerpressAI | 13/7/2026 | 13/7/2026 | Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2. | |
| Aplazada | Media (6.9) | 0.37% | — | Praisonai AgentmailAI | 11/7/2026 | 13/7/2026 | PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender addresses. Attackers can POST crafted message.received events to the webhook endpoint to inject arbitrary content into the agent and trigger replies to… | |
| Aplazada | Media (4.4) | 0.34% | — | Print PDF Email BY PrintfriendlyAI | 11/7/2026 | 13/7/2026 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and including, 5.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (5.8) | 0.38% | — | Axllent MailpitAI | 10/7/2026 | 13/7/2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.2, the remediation shipped for CVE-2026-27808 is incomplete because the tools.IsInternalIP deny-list in internal/tools/net.go relies on Go's standard library classification helpers and does not block IPv6 transition mechanisms or prefixes such as… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.8) | 0.45% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Pendiente de análisis | Crítica (9.3) | 0.43% | — | Guardrails-detectorsAI | 10/7/2026 | 31/8/2026 | A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary URLs or local file reads, potentially… | |
| Aplazada | Media (4.9) | 0.51% | — | Mail MintAI | 10/7/2026 | 14/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to generic SQL Injection via the 'recipients' parameter in all versions up to, and including, 1.24.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on… | |
| Pendiente de análisis | Crítica (9.3) | 0.53% | — | Guardrails-detectorsAI | 10/7/2026 | 30/9/2026 | A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive information, including credentials from… | |
| Aplazada | Media (5.1) | 0.16% | — | Samsung EmailAI | 10/7/2026 | 10/7/2026 | Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox. | |
| Aplazada | Media (6.1) | 0.36% | — | Brevo Newsletter Smtp Email Marketing Subscribe FormsAI | 10/7/2026 | 10/7/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the page parameter in all versions up to, and including, 3.1.77 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Modificada | Crítica (9.2) | 1.4% | 💥 Exploit | Acymailing | 9/7/2026 | 23/7/2026 | Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage. | |
| Aplazada | Alta (7.2) | 0.59% | — | Connect Contact Form 7 AND MailchimpAI | 9/7/2026 | 9/7/2026 | The Connect Contact Form 7 and Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Mailchimp Merge Field Values in all versions up to, and including, 0.9.78.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Media (4.9) | 0.44% | — | Mailmint Mail MintAI | 9/7/2026 | 9/7/2026 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to time-based SQL Injection via the 'contact_ids' parameter in all versions up to, and including, 1.24.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation… | |
| Aplazada | Media (6.4) | 0.35% | — | AcymailingAI | 9/7/2026 | 9/7/2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' attribute in all versions up to, and including, 10.10.2 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Pendiente de análisis | Alta (8.8) | 0.18% | — | OpenjdkAIUbuntuAIMailcapAIFreedesktop Xdg-desktop-portal-gtkAI | 8/7/2026 | 14/7/2026 | A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk… | |
| Pendiente de análisis | Media (6.3) | 0.27% | — | Trustyai Service OperatorAIGorchAINemoguardrailsAI | 8/7/2026 | 31/8/2026 | A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enabled, these services can expose their communication channels without requiring users to prove their identity. This allows any other program within the cluster to access the… | |
| Aplazada | Alta (7.1) | 0.51% | — | Circl AIL FrameworkAI | 5/7/2026 | 6/7/2026 | AIL Framework contains a path traversal vulnerability in its PDF object handling. Prior to commit 14c618fce4d1df02358717c48ea903706abecdf2, the PDF.get_filepath() function constructed a file path by joining the configured PDF storage directory with a path derived from a PDF object identifier, without verifying that… | |
| Analizada | Crítica (9.8) | 0.56% | — | Trailofbits Fickling | 4/7/2026 | 10/7/2026 | In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in the shared… | |
| Analizada | Alta (8.8) | 0.59% | — | Trailofbits Fickling | 4/7/2026 | 10/7/2026 | Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and atexit in the UNSAFE_IMPORTS denylist (fickle.py). Because these modules are absent from the denylist, fickling's check_safety() function returns LIKELY_SAFE with zero findings for… | |
| Aplazada | Media (4.3) | 0.47% | — | Blog Dash Email SubscribersAI | 2/7/2026 | 2/7/2026 | The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.9.27. This is due to the plugin not properly verifying that a user is authorized to perform an action. This… | |
| Analizada | Alta (7.3) | 0.36% | — | Torchbox Wagtail | 1/7/2026 | 6/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin… | |
| Analizada | Media (4.3) | 0.27% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, a low-level user with the "Can submit translation" permission can create translations for any page, including those they do not have permissions for. This issue has been fixed in versions 7.0.8, 7.3.3, and… | |
| Analizada | Media (6.5) | 0.34% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, due to a missing permission check on the image preview endpoint, a user with access to the Wagtail admin can preview any image. The existing data of the image object itself is not exposed. The… | |
| Analizada | Baja (2.7) | 0.37% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, an authenticated admin user can trigger expensive rendition processing with purposefully crafted filter specs resulting in potentially service degradation. The vulnerability is not exploitable by an… |