Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.27% | — | Torchbox Wagtail | 1/7/2026 | 2/7/2026 | Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, the Documents and Images chooser's chosen endpoint incorrectly listed items for which the user has not been granted choose permission. A user with access to the Wagtail admin could see the filename and… | |
| Aplazada | Alta (7.7) | 2.3% | — | Luci-app-tailscale-communityAI | 29/6/2026 | 14/7/2026 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are improperly quoted within a… | |
| Aplazada | Media (4.3) | 0.14% | — | Gmail SmtpAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions. | |
| Aplazada | Media (5.4) | 0.29% | — | Omnisend Email Marketing FOR WoocommerceAI | 26/6/2026 | 26/6/2026 | Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions. | |
| Aplazada | Alta (8.3) | 0.30% | — | Mailchimp BlockAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | Siteground Email MarketingAI | 26/6/2026 | 26/6/2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wedevs WemailAI | 26/6/2026 | 18/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows Reflected XSS.This issue affects weMail: from n/a through 2.1.2. | |
| Aplazada | Alta (8.8) | 0.51% | — | Email Address Encoder Email Encoder PremiumAITillkruss Email Address EncoderAI | 25/6/2026 | 25/6/2026 | The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to perform Stored XSS attacks | |
| Aplazada | Alta (8.8) | 0.71% | — | MailerupAI | 24/6/2026 | 25/6/2026 | Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /api/auth/register/, in MailerUp <1.0.1 allows a remote, unauthenticated attacker to self-register a working account on instances where registration is intended to be restricted, because the endpoint… | |
| Aplazada | Media (5.3) | 0.51% | — | MailerupAI | 24/6/2026 | 25/6/2026 | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mailerup <1.0.0 on all platforms allows remote unauthenticated attackers to redirect victims to arbitrary external sites and conduct phishing attacks via a crafted u query parameter, because the URL… | |
| Aplazada | Alta (7.2) | 0.36% | — | Email Javascript CloakAI | 24/6/2026 | 25/6/2026 | The Email JavaScript Cloak plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email' shortcode in all versions up to, and including, 1.03 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Ninguna (0) | 0.39% | — | Userlog-details.phpAI | 23/6/2026 | 25/6/2026 | Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would have any malicious JavaScript payload… | |
| Aplazada | Media (5.1) | 0.58% | — | AILAI | 22/6/2026 | 22/6/2026 | AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such as after successfully completing the password-authentication stage, could submit an unlimited number of OTP guesses. This could enable brute-force guessing of a… | |
| Aplazada | Alta (8.3) | 0.44% | — | Circl AIL FrameworkAI | 22/6/2026 | 22/6/2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL user can supply crafted object identifiers through the investigation workflow to cause file paths to resolve outside the intended image, favicon, or screenshot… | |
| Aplazada | Media (5.3) | 0.51% | — | Circl AIL FrameworkAI | 19/6/2026 | 22/6/2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifiers through the s1 and s2 query parameters and, prior to the fix, attempted to retrieve and compare item contents without first verifying that both referenced items existed as valid AIL objects.… | |
| Aplazada | Alta (7.1) | 0.44% | — | SeppmailAI | 18/6/2026 | 22/6/2026 | SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An attacker can exploit this to create new files outside the intended directory, potentially placing files in web-accessible locations. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wedevs WemailAI | 17/6/2026 | 17/6/2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Integration FOR Mailchimp AND Contact Form 7AI | 15/6/2026 | 17/6/2026 | Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. | |
| Aplazada | Alta (7.5) | 0.48% | — | Omnisend Email Marketing FOR WoocommerceAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Speakout Email PetitionsAI | 15/6/2026 | 17/6/2026 | Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions. | |
| Aplazada | Alta (7.2) | 0.54% | — | YaymailAI | 15/6/2026 | 17/6/2026 | Shop manager PHP Object Injection in YayMail <= 4.3.3 versions. | |
| Aplazada | Alta (7.5) | 0.46% | — | Feuerhamster MailformAI | 15/6/2026 | 17/6/2026 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request. | |
| Aplazada | Alta (8.7) | 0.54% | — | Agenticmail MCPAI | 12/6/2026 | 17/6/2026 | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and… | |
| Aplazada | Alta (7.1) | 0.27% | — | Wpvibes WP Mail LOGAI | 11/6/2026 | 23/7/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2. | |
| Analizada | Alta (7.8) | 0.36% | — | Microsoft Windows Narrator Braille | 9/6/2026 | 23/7/2026 | Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally. |