Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.46% | — | Sp-php-email-handlerAI | 27/11/2024 | 17/6/2026 | sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnerable to abuse, as the script allows anybody to specify arbitrary email recipients and include user-provided content in confirmation emails. This could enable malicious actors to use your server to… | |
| Aplazada | Media (6.1) | 0.36% | — | Debounce Email ValidatorAI | 23/11/2024 | 17/6/2026 | The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', and 'key' parameters in all versions up to, and including, 5.6.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Alta (8.8) | 1.3% | — | Krishaweb Contact Form 7 Email ADD ON | 21/11/2024 | 17/6/2026 | The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the cf7_email_add_on_add_admin_template() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP… | |
| Analizada | Media (6.4) | 0.37% | — | I13websolution Email Subscription Popup | 19/11/2024 | 17/6/2026 | The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.43% | 💥 PoC | Ferozo EmailAI | 18/11/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Ferozo Email version 1.1 allows a local attacker to execute arbitrary code via a crafted payload to the PDF preview component. | |
| Analizada | Alta (7.5) | 0.84% | — | Cisco Email Security Appliance | 18/11/2024 | 17/6/2026 | A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition. The vulnerability… | |
| Analizada | Media (5.3) | 0.77% | — | Cisco Enterprise Chat AND Email | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in authentication responses that are sent back from the application as part of an… | |
| Analizada | Media (6.1) | 0.53% | — | Cisco Enterprise Chat AND Email | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An… | |
| Analizada | Media (6.1) | 0.59% | — | Cisco Enterprise Chat AND Email | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could… | |
| Analizada | Media (6.1) | 0.51% | — | Cisco Enterprise Chat AND Email | 15/11/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the interface of an affected device. The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An… | |
| Analizada | Alta (7.5) | 0.64% | — | Cisco Enterprise Chat AND Email | 6/11/2024 | 17/6/2026 | A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of Media Routing Peripheral Interface… | |
| Aplazada | Media (4.3) | 0.39% | — | Matt Miller Send Emails With MandrillAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Matt Miller Send Emails with Mandrill send-emails-with-mandrill allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Send Emails with Mandrill: from n/a through <= 1.4.1. | |
| Aplazada | Alta (8.3) | 0.34% | — | Upqode Plum Spin Wheel AND Email Pop-upAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. | |
| Aplazada | Media (5.3) | 0.40% | — | Upqode Plum Spin Wheel AND Email Pop-upAI | 1/11/2024 | 17/6/2026 | Access Control vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows . This issue affects Plum: Spin Wheel & Email Pop-up: from n/a through 2.0. | |
| Modificada | Media (4.8) | 0.28% | — | Villatheme Woocommerce Email Template Customizer | 17/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email Template Customizer for WooCommerce email-template-customizer-for-woo allows Stored XSS.This issue affects Email Template Customizer for WooCommerce: from n/a through <= 1.2.9.1. | |
| Aplazada | Crítica (9.3) | 0.41% | — | Wpfactory Emails Verification FOR WoocommerceAI | 17/10/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Email Verification for WooCommerce emails-verification-for-woocommerce allows SQL Injection.This issue affects Email Verification for WooCommerce: from n/a through <= 2.8.10. | |
| Analizada | Media (4.3) | 0.18% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 10/10/2024 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible for unauthenticated… | |
| Analizada | Media (6.3) | 0.50% | — | Icegram Email Subscribers & Newsletters | 2/10/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to execute an action that does not properly… | |
| Analizada | Media (4.3) | 0.36% | — | Icegram Email Subscribers & Newsletters | 26/9/2024 | 17/6/2026 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'preview_email_template_design' function in all versions up to, and including, 5.7.34. This makes it… | |
| Analizada | Crítica (9.8) | 1.4% | — | Cellopoint Secure Email Gateway | 20/9/2024 | 17/6/2026 | Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing authentication and obtaining system administrator privileges. | |
| Analizada | Media (5.4) | 0.31% | — | Khromov Email Obfuscate Shortcode | 13/9/2024 | 17/6/2026 | The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-obfuscate' shortcode in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.38% | — | Boopathirajan WP Test Email | 13/9/2024 | 17/6/2026 | The WP Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Analizada | Media (6.1) | 0.31% | — | Forcepoint Email Security | 4/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email Security: before 8.5.5 HF003. | |
| Analizada | Alta (8.8) | 0.21% | — | Sendinblue Newsletter, Smtp, Email Marketing AND Subscribe | 26/8/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue.This issue affects Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue: from n/a through 3.1.82. | |
| Modificada | Media (6.1) | 0.31% | — | Wedevs Wemail | 18/8/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs weMail wemail allows DOM-Based XSS.This issue affects weMail: from n/a through <= 1.14.5. |