Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

472 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.0%—Proofpoint Spam Engine13/10/202117/6/2026
Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.
ModificadaMedia (5.4)0.62%—Trumani Stop Spammers6/9/202117/6/2026
The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2021.18 does not escape some of its settings, allowing high privilege users such as admin to set Cross-Site Scripting payloads in them even when the unfiltered_html capability is disallowed
ModificadaMedia (6.1)1.0%—Phpipam23/6/202117/6/2026
phpIPAM 1.4.3 allows Reflected XSS via app/dashboard/widgets/ipcalc-result.php and app/tools/ip-calculator/result.php of the IP calculator.
ModificadaAlta (7)0.35%—PAM Setquota Project PAM Setquota22/6/202117/6/2026
pam_setquota.c in the pam_setquota module before 2020-05-29 for Linux-PAM allows local attackers to set their quota on an arbitrary filesystem, in certain situations where the attacker's home directory is a FUSE filesystem mounted under /home.
ModificadaMedia (6.8)0.33%—Yubico Pam-u2fFedoraproject Fedora26/5/202117/6/2026
Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would still need to physically possess and…
ModificadaAlta (7.5)4.7%💥 ExploitCleantalk Spam Protection, Antispam, Firewall17/5/202117/6/2026
It was possible to exploit an Unauthenticated Time-Based Blind SQL Injection vulnerability in the Spam protection, AntiSpam, FireWall by CleanTalk WordPress Plugin before 5.153.4. The update_log function in lib/Cleantalk/ApbctWP/Firewall/SFW.php included a vulnerable query that could be injected via the User-Agent…
ModificadaMedia (6.1)5.7%💥 ExploitTrumani Stop Spammers6/5/202117/6/2026
The Stop Spammers WordPress plugin before 2021.9 did not escape user input when blocking requests (such as matching a spam word), outputting it in an attribute after sanitising it to remove HTML tags, which is not sufficient and lead to a reflected Cross-Site Scripting issue.
ModificadaCrítica (9.8)6.1%—Apache SpamassassinDebian LinuxFedoraproject Fedora25/3/202117/6/2026
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use update channels or 3rd party .cf files…
ModificadaAlta (7.2)1.4%—Cleantalk Anti-spam18/3/202117/6/2026
Unvalidated input in the Anti-Spam by CleanTalk WordPress plugin, versions before 5.149, lead to multiple authenticated SQL injection vulnerabilities, however, it requires high privilege user (admin+).
ModificadaCrítica (9.8)1.0%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user18/3/202117/6/2026
HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL parameter of email pages without privilege.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a SQL injection flaw. Attackers can inject and launch SQL commands in a URL parameter of specific cgi pages.
ModificadaAlta (7.6)0.61%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock contains a vulnerability of SQL Injection. Attackers can inject and launch SQL commands in a URL parameter.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate user parameters on multiple login pages. Attackers can use the vulnerability to inject JavaScript syntax for XSS attacks.
ModificadaMedia (6.1)0.62%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-userHgiga Ssr45 Isherlock-antispamHgiga Ssr45 Isherlock-user31/12/202017/6/2026
HGiga MailSherlock does not validate specific URL parameters properly that allows attackers to inject JavaScript syntax for XSS attacks.
ModificadaCrítica (9.8)1.7%—Hgiga Msr45 Isherlock-antispamHgiga Msr45 Isherlock-auditHgiga Msr45 Isherlock-baseHgiga Msr45 Isherlock-user+631/12/202017/6/2026
HGiga MailSherlock contains weak authentication flaw that attackers grant privilege remotely with default password generation mechanism.
ModificadaCrítica (9.8)2.8%—Jiransecurity Spamsniper27/12/202017/6/2026
Spamsniper 5.0 ~ 5.2.7 contain a stack-based buffer overflow vulnerability caused by improper boundary checks when parsing MAIL FROM command. It leads remote attacker to execute arbitrary code via crafted packet.
ModificadaMedia (5.3)0.51%—Titanhq Spamtitan23/12/202017/6/2026
SpamTitan before 7.09 allows attackers to tamper with backups, because backups are not encrypted.
ModificadaCrítica (9.8)2.0%—Linux-pam18/12/202017/6/2026
A flaw was found in Linux-Pam in versions prior to 1.5.1 in the way it handle empty passwords for non-existing users. When the user doesn't exist PAM try to authenticate with root and in the case of an empty password it successfully authenticate.
ModificadaCrítica (9.8)1.7%—PAM Tacplus Project PAM Tacplus26/10/202017/6/2026
libtac in pam_tacplus through 1.5.1 lacks a check for a failure of RAND_bytes()/RAND_pseudo_bytes(). This could lead to use of a non-random/predictable session_id.
ModificadaAlta (7.2)3.4%—Titanhq Spamtitan17/9/202017/6/2026
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This restricted shell can be bypassed after changing the properties of the user admin in the operating system file /etc/passwd.…
ModificadaAlta (7.2)1.6%—Titanhq Spamtitan17/9/202017/6/2026
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan…
ModificadaAlta (8.8)7.1%💥 ExploitTitanhq Spamtitan17/9/202017/6/2026
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.
ModificadaAlta (8.8)7.5%💥 ExploitTitanhq Spamtitan17/9/202017/6/2026
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform…
ModificadaMedia (6.5)7.1%💥 ExploitTitanhq Spamtitan17/9/202017/6/2026
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.
ModificadaAlta (8.8)9.6%💥 ExploitTitanhq Spamtitan17/9/202017/6/2026
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.
Orbitaley — Vulnerabilidades