Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.42% | — | MailerpressAI | 9/6/2026 | 23/7/2026 | The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Content Field in all versions up to, and including, 2.0.4 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Analizada | Crítica (9.6) | 0.49% | — | Guardrailsai Guardrails AI | 5/6/2026 | 23/7/2026 | Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. Aany user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026 may be affected. Security researchers… | |
| Aplazada | Media (6.4) | 0.19% | — | FPW Category ThumbnailsAI | 2/6/2026 | 22/7/2026 | The FPW Category Thumbnails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the 'fpw_fs_get_file' AJAX action in all versions up to, and including, 1.9.5. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.5) | 0.31% | 💥 PoC | Code-projects Student Details Management SystemAI | 30/5/2026 | 22/7/2026 | A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the argument roll results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. | |
| Analizada | Alta (8.8) | 0.51% | — | Jenkins Email Extension | 27/5/2026 | 17/6/2026 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary… | |
| Analizada | Crítica (9.3) | 0.38% | — | Tassos Advanced Custom FieldsTassos Convert FormsTassos EngageboxTassos Google Structured Data+4 | 27/5/2026 | 17/6/2026 | The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites. | |
| Aplazada | Media (6.4) | 0.32% | — | Auto ThumbnailAI | 27/5/2026 | 17/6/2026 | The Auto Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'thumbnails' shortcode in all versions up to, and including, 1.0. This is due to insufficient input sanitization and output escaping on the shortcode's 'width' and 'height' attributes in the athn_thumbnails() function, which… | |
| Aplazada | Media (6.4) | 0.32% | — | Single MailchimpAI | 27/5/2026 | 17/6/2026 | The Single Mailchimp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'single-mailchimp' shortcode in all versions up to, and including, 1.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes (autocomplete, label, placeholder, btn_text,… | |
| Aplazada | Media (6.4) | 0.32% | — | MY Email ShortcodeAI | 27/5/2026 | 17/6/2026 | The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions up to, and including, 0.91 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Pendiente de análisis | Media (5.7) | 0.68% | — | Zohocorp Zoho MailAI | 26/5/2026 | 23/7/2026 | Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. | |
| Aplazada | Baja (2.9) | 0.54% | — | Fraillt BitseryAI | 26/5/2026 | 23/7/2026 | A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been… | |
| Aplazada | Media (4.4) | 0.26% | 💥 PoC | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. | |
| Aplazada | Alta (7.2) | 0.45% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element with the attributeName attribute. | |
| Aplazada | Baja (3.7) | 0.54% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. | |
| Aplazada | Media (6.5) | 0.48% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information disclosure or access-control bypass. | |
| Aplazada | Media (6.5) | 0.45% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information disclosure or privilege escalation via a text/html email message. | |
| Aplazada | Alta (7.5) | 0.51% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been removed in 1.6.16 and 1.7.1.) | |
| Aplazada | Alta (7.2) | 0.27% | — | Roundcube WebmailAI | 25/5/2026 | 24/7/2026 | Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. The issue stems from an insufficient fix for CVE-2026-35540. | |
| Aplazada | Alta (8.1) | 0.89% | 💥 PoC | Roundcube WebmailAI | 25/5/2026 | 25/9/2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. | |
| Pendiente de análisis | Media (6.7) | 0.12% | — | Dell VxrailAI | 22/5/2026 | 23/7/2026 | Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges… | |
| Aplazada | Media (4.3) | 0.29% | — | Mail MintAI | 21/5/2026 | 23/7/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPFunnels Team Mail Mint allows Retrieve Embedded Sensitive Data. This issue affects Mail Mint: from n/a through 1.19.5. | |
| Aplazada | Alta (8.8) | 0.44% | — | AcymailingAI | 20/5/2026 | 24/7/2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 10.8.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible… | |
| Aplazada | Media (6.1) | 0.27% | — | Email EncoderAI | 20/5/2026 | 24/7/2026 | The Email Encoder WordPress plugin before 2.4.7 does not escape email addresses retrieved via user input, allowing unauthenticated attackers to perform Stored XSS attacks | |
| Aplazada | Alta (7.4) | 0.41% | — | Mailcow-dockerizedAI | 20/5/2026 | 24/7/2026 | mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-controlled Postfix queue fields into DataTables rows, and renders several of those fields as HTML without adequate output… | |
| Aplazada | Alta (7.5) | 0.51% | — | Constantcontact Creative MailAI | 20/5/2026 | 21/8/2026 | The Creative Mail – Easier WordPress & WooCommerce Email Marketing plugin for WordPress is vulnerable to SQL Injection via the 'checkout_uuid' parameter in all versions up to, and including, 1.6.9. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing… |