Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3270 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.29% | — | Mailcow DockerizedAI | 21/4/2026 | 17/6/2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the user dashboard's "Seen successful connections" (login history) renders the client IP from login logs without HTML escaping. Because the server trusts the X-Real-IP header as the source IP for logging, an… | |
| Aplazada | Media (6) | 0.27% | — | Mailcow DockerizedAI | 21/4/2026 | 17/6/2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, no administrator verification takes place when deleting Forwarding Hosts with `/api/v1/delete/fwdhost`. Any authenticated user can call this API. Checks are only applied for edit/add actions, but deletion can… | |
| Aplazada | Alta (8.9) | 0.55% | — | Mailcow DockerizedAI | 21/4/2026 | 17/6/2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the Quarantine details modal injects attachment filenames into HTML without escaping, allowing arbitrary HTML/JS execution. An attacker can deliver an email with a crafted attachment name so that when an admin… | |
| Aplazada | Crítica (9.3) | 0.44% | — | Mailcow DockerizedAI | 21/4/2026 | 17/6/2026 | mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover logs render the EMailAddress value (logged as the "user" field) without HTML escaping. By submitting an unauthenticated Autodiscover request with a crafted EMailAddress… | |
| Aplazada | Alta (7.2) | 0.45% | — | Mailcow DockerizedAI | 21/4/2026 | 17/6/2026 | mailcow: dockerized is an open source groupware/email suite based on docker. Versions prior to 2026-03b have a second-order SQL injection vulnerability in the quarantine_category field via the Mailcow API. The /api/v1/add/mailbox endpoint stores quarantine_category without validation or sanitization. This value is… | |
| Aplazada | Baja (3.5) | 0.21% | — | Email EncoderAI | 20/4/2026 | 17/6/2026 | The Email Encoder WordPress plugin before 2.3.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Alta (8.1) | 1.0% | — | Sagredo QmailAI | 16/4/2026 | 17/6/2026 | sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c. | |
| Aplazada | Media (6.4) | 0.32% | — | Email Encoder Protect Email Addresses AND Phone NumbersAI | 16/4/2026 | 17/6/2026 | The Email Encoder – Protect Email Addresses and Phone Numbers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'eeb_mailto' shortcode in all versions up to, and including, 2.4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.58% | — | AcymailingAI | 16/4/2026 | 17/6/2026 | The AcyMailing plugin for WordPress is vulnerable to privilege escalation in all versions From 9.11.0 up to, and including, 10.8.1 due to a missing capability check on the `wp_ajax_acymailing_router` AJAX handler. This makes it possible for authenticated attackers, with Subscriber-level access and above, to access… | |
| Aplazada | Alta (8.7) | 0.57% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files. | |
| Aplazada | Crítica (9.3) | 0.98% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | |
| Analizada | Media (4.9) | 0.54% | — | Kamailio | 8/4/2026 | 24/7/2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted SIP packet if a successful user authentication… | |
| Analizada | Alta (7.5) | 0.55% | — | Kamailio | 8/4/2026 | 24/7/2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts… | |
| Aplazada | Media (5.3) | 0.32% | — | Mailercloud-integrate-webforms-synchronize-contactsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-synchronize-contacts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mailercloud – Integrate webforms and synchronize website… | |
| Aplazada | Alta (7.6) | 0.38% | — | Yaycommerce YaymailAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through <= 4.3.3. | |
| Analizada | Alta (8.7) | 0.19% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based… | |
| Analizada | Media (5.3) | 0.23% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header. This means cross-site scripting (XSS) attacks were logged but not blocked. Any user who… | |
| Analizada | Alta (8.7) | 0.24% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed… | |
| Analizada | Alta (8.2) | 0.55% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. | |
| Analizada | Media (5.3) | 0.51% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. | |
| Analizada | Media (5.3) | 0.53% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Analizada | Media (5.3) | 0.53% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Analizada | Media (4.2) | 0.31% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. | |
| Analizada | Media (6.5) | 0.39% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. | |
| Analizada | Media (6.1) | 0.35% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. |