Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3270 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.1)0.36%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
AnalizadaAlta (7.5)0.60%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
AnalizadaAlta (8.7)0.42%—Bulwarkmail Webmail2/4/202624/7/2026
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings…
AnalizadaAlta (8.7)0.27%—Bulwarkmail Webmail2/4/202624/7/2026
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in…
AnalizadaAlta (7.8)0.35%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters.
AnalizadaAlta (7.8)0.43%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
AnalizadaMedia (6.3)0.19%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
AnalizadaAlta (7.7)0.35%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
AnalizadaAlta (7.7)0.19%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.
AnalizadaAlta (7.8)0.48%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.
AnalizadaMedia (6.3)0.37%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
AnalizadaMedia (5.3)0.31%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.
AnalizadaMedia (5.3)0.16%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates.
AnalizadaMedia (5.3)0.42%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.
AnalizadaMedia (5.3)0.38%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.
AnalizadaMedia (5.3)0.40%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.
AnalizadaMedia (6.3)0.42%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails.
AnalizadaMedia (4.9)0.38%—Seppmail Secure Email Gateway2/4/202617/6/2026
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.
AnalizadaBaja (3.8)0.41%—Sonicwall Email Security31/3/202624/7/2026
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.
AnalizadaBaja (2.7)0.47%—Sonicwall Email Security31/3/202624/7/2026
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.
AnalizadaMedia (4.8)0.29%—Sonicwall Email Security31/3/202624/7/2026
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.
AnalizadaCrítica (9.3)0.47%—Ahsanriaz26gmailcom Sales AND Inventory System30/3/202617/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (6.1)0.31%—Ahsanriaz26gmailcom Sales AND Inventory System30/3/202617/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted…
ModificadaMedia (6.1)0.31%—Ahsanriaz26gmailcom Sales AND Inventory System30/3/202617/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_supplier.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted…
ModificadaMedia (6.1)0.31%—Ahsanriaz26gmailcom Sales AND Inventory System30/3/202617/6/2026
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.