Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3270 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 0.46% | — | Mailenable | 23/3/2026 | 17/6/2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the StartDate parameter in the FreeBusy.aspx… | |
| Analizada | Media (5.1) | 0.46% | — | Mailenable | 23/3/2026 | 17/6/2026 | MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the SelectedIndex parameter in the… | |
| Analizada | Baja (2.1) | 0.37% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 23/3/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /view_product.php of the component HTTP POST Request Handler. Executing a manipulation of the argument searchtxt can lead to sql injection. The attack may be performed from… | |
| Analizada | Baja (2.1) | 0.37% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 23/3/2026 | 17/6/2026 | A security flaw has been discovered in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_payments.php of the component HTTP POST Request Handler. Performing a manipulation of the argument searchtxt results in sql injection. The attack is… | |
| Analizada | Baja (2.1) | 0.47% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 23/3/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /view_customers.php of the component HTTP POST Request Handler. Such manipulation of the argument searchtxt leads to sql injection. The attack can be executed remotely. The exploit is publicly… | |
| Analizada | Baja (2.1) | 0.37% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 23/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /view_category.php of the component HTTP POST Request Handler. This manipulation of the argument searchtxt causes sql injection. Remote exploitation of the attack is possible. The exploit has… | |
| Modificada | Baja (2.1) | 0.35% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 23/3/2026 | 17/6/2026 | A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /update_supplier.php of the component HTTP GET Request Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public… | |
| Aplazada | Media (4.9) | 0.59% | — | EmailkitAI | 21/3/2026 | 17/6/2026 | The EmailKit – Email Customizer for WooCommerce & WP plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, and including, 1.6.3. This is due to the action() function in the TemplateData class passing user-supplied input from the 'emailkit-editor-template' REST API… | |
| Analizada | Alta (7.7) | 0.45% | — | Mrsilaz MFA Mail | 17/3/2026 | 17/6/2026 | The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider. | |
| Analizada | Media (5.2) | 0.21% | — | Cps-it Mailqueue | 17/3/2026 | 17/6/2026 | The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker may exploit this to execute untrusted serialized code. Note that an active exploit requires write access to the directory configured at $GLOBALS['TYPO3_CONF_VARS']['MAIL']['transport_spool_filepath']. | |
| Aplazada | Media (6.4) | 0.23% | — | MailerpressAI | 13/3/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in MailerPress Team MailerPress mailerpress allows Server Side Request Forgery.This issue affects MailerPress: from n/a through <= 1.4.2. | |
| Analizada | Media (4) | 0.08% | — | Fortinet FortivoiceFortinet FortirecorderFortinet Fortimail | 10/3/2026 | 17/6/2026 | A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorder 6.4 all versions,… | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 9/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file sales_invoice1.php of the component GET Parameter Handler. This manipulation of the argument sellid causes sql injection. It is possible to initiate the attack remotely. The exploit has… | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 9/3/2026 | 17/6/2026 | A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file purchase_invoice.php of the component GET Parameter Handler. The manipulation of the argument purchaseid results in sql injection. The attack may be performed from remote. The exploit has been made… | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 9/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file dashboard.php of the component Search. The manipulation of the argument searchtxt leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 9/3/2026 | 17/6/2026 | A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file check_supplier_details.php of the component POST Parameter Handler. Executing a manipulation of the argument stock_name1 can lead to sql injection. The attack can be executed… | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 8/3/2026 | 17/6/2026 | A vulnerability was identified in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function of the file /check_item_details.php. The manipulation of the argument stock_name1 leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 8/3/2026 | 17/6/2026 | A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This impacts an unknown function of the file /check_customer_details.php of the component POST Handler. Executing a manipulation of the argument stock_name1 can lead to sql injection. The attack can be launched remotely. The exploit has… | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 8/3/2026 | 17/6/2026 | A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown function of the file /add_stock.php. Performing a manipulation of the argument cost results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.49% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 8/3/2026 | 17/6/2026 | A vulnerability has been found in SourceCodester Sales and Inventory System up to 1.0. The impacted element is an unknown function of the file /add_sales_print.php. Such manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Aplazada | Media (4.8) | 0.36% | — | Perfopsone MailarchiverAI | 7/3/2026 | 17/6/2026 | The MailArchiver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Baja (2.1) | 0.47% | — | Hsclabs MailinspectorAI | 6/3/2026 | 17/6/2026 | A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown functionality of the file /mailinspector/mliUserValidation.php of the component URL Handler. The manipulation of the argument error_description results in cross site scripting. The attack may be performed… | |
| Modificada | Crítica (10) | 1.0% | — | Seppmail | 5/3/2026 | 17/6/2026 | Arbitrary File Write via Path Traversal upload to Remote Code Execution in SeppMail User Web Interface. The affected feature is the large file transfer (LFT). This issue affects SeppMail: 15.0.2.1 and before | |
| Analizada | Alta (7.8) | 0.20% | — | Seppmail | 4/3/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.1 improperly validates S/MIME certificates issued for email addresses containing whitespaces, allowing signature spoofing. | |
| Analizada | Media (6.9) | 0.43% | — | Seppmail | 4/3/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.1 decrypts inline PGP messages without isolating them from surrounding unencrypted content, allowing exposure of sensitive information to an unauthorized actor. |