Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

4598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.27%—Torchbox Wagtail1/7/20262/7/2026
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and…
AplazadaAlta (7.7)2.3%—Luci-app-tailscale-communityAI29/6/202614/7/2026
luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a…
AplazadaMedia (4.3)0.14%—Gmail SmtpAI26/6/202626/6/2026
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
AplazadaMedia (5.4)0.29%—Omnisend Email Marketing FOR WoocommerceAI26/6/202626/6/2026
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
AplazadaAlta (8.3)0.30%—Mailchimp BlockAI26/6/202626/6/2026
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
AplazadaMedia (5.3)0.29%—Siteground Email MarketingAI26/6/202626/6/2026
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
AplazadaAlta (7.1)0.25%—Wedevs WemailAI26/6/202618/9/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2.
AplazadaAlta (8.8)0.51%—Email Address Encoder Email Encoder PremiumAITillkruss Email Address EncoderAI25/6/202625/6/2026
The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks
AplazadaAlta (8.8)0.71%—MailerupAI24/6/202625/6/2026
Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where registration is intended to be restricted, because the endpoint…
AplazadaMedia (5.3)0.51%—MailerupAI24/6/202625/6/2026
Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL…
AplazadaAlta (7.2)0.36%—Email Javascript CloakAI24/6/202625/6/2026
The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaNinguna (0)0.39%—Userlog-details.phpAI23/6/202625/6/2026
Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would have any malicious JavaScript payload…
AplazadaMedia (5.1)0.58%—AILAI22/6/202622/6/2026
AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a…
AplazadaAlta (8.3)0.44%—Circl AIL FrameworkAI22/6/202622/6/2026
A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot…
AplazadaMedia (5.3)0.51%—Circl AIL FrameworkAI19/6/202622/6/2026
AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects.…
AplazadaAlta (7.1)0.44%—SeppmailAI18/6/202622/6/2026
SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations.
AplazadaAlta (7.1)0.28%—Wedevs WemailAI17/6/202617/6/2026
The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver…
AplazadaCrítica (9.8)0.56%—Integration FOR Mailchimp AND Contact Form 7AI15/6/202617/6/2026
Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.
AplazadaAlta (7.5)0.48%—Omnisend Email Marketing FOR WoocommerceAI15/6/202617/6/2026
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions.
AplazadaCrítica (9.3)0.40%—Speakout Email PetitionsAI15/6/202617/6/2026
Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.
AplazadaAlta (7.2)0.54%—YaymailAI15/6/202617/6/2026
Shop manager PHP Object Injection in YayMail <= 4.3.3 versions.
AplazadaAlta (7.5)0.46%—Feuerhamster MailformAI15/6/202617/6/2026
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
AplazadaAlta (8.7)0.54%—Agenticmail MCPAI12/6/202617/6/2026
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and…
AplazadaAlta (7.1)0.27%—Wpvibes WP Mail LOGAI11/6/202623/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
AnalizadaAlta (7.8)0.36%—Microsoft Windows Narrator Braille9/6/202623/7/2026
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.