Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.57% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files. | |
| Aplazada | Crítica (9.3) | 0.98% | — | Openfind MailgatesAIOpenfind MailauditAI | 16/4/2026 | 17/6/2026 | MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code. | |
| Pendiente de análisis | Alta (8.4) | 0.38% | — | Sailpoint IdentityiqAI | 15/4/2026 | 17/6/2026 | IdentityIQ 8.5, all IdentityIQ 8.5 patch levels prior to 8.5p2, IdentityIQ 8.4, and all IdentityIQ 8.4 patch levels prior to 8.4p4 allow authenticated users assigned the Debug Pages Read Only capability or any custom capability with the ViewAccessDebugPage SPRight to incorrectly create new IdentityIQ objects. Until a… | |
| Aplazada | Media (5.5) | 0.41% | — | Phpgurukul Daily Expense Tracking SystemAI | 13/4/2026 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Daily Expense Tracking System 1.1. Affected is an unknown function of the file /register.php. The manipulation of the argument email results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. | |
| Analizada | Alta (8.5) | 0.30% | — | Circl AIL Framework | 8/4/2026 | 24/7/2026 | AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a stored cross-site scripting (XSS) vulnerability was identified in the modal item preview functionality. When item content longer than 800 characters was processed, attacker-controlled content was returned… | |
| Analizada | Media (4.9) | 0.54% | — | Kamailio | 8/4/2026 | 24/7/2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in the auth module of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted SIP packet if a successful user authentication… | |
| Analizada | Alta (7.5) | 0.55% | — | Kamailio | 8/4/2026 | 24/7/2026 | Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts… | |
| Analizada | Alta (7.5) | 0.21% | — | Trailofbits Rfc3161-client | 8/4/2026 | 24/7/2026 | rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library… | |
| Aplazada | Media (5.3) | 0.32% | — | Mailercloud-integrate-webforms-synchronize-contactsAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in mailercloud Mailercloud – Integrate webforms and synchronize website contacts mailercloud-integrate-webforms-synchronize-contacts allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mailercloud – Integrate webforms and synchronize website… | |
| Aplazada | Alta (7.6) | 0.38% | — | Yaycommerce YaymailAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YayMail yaymail allows Blind SQL Injection.This issue affects YayMail: from n/a through <= 4.3.3. | |
| Analizada | Alta (8.7) | 0.19% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based… | |
| Analizada | Media (5.3) | 0.23% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header. This means cross-site scripting (XSS) attacks were logged but not blocked. Any user who… | |
| Analizada | Alta (8.7) | 0.24% | — | Bulwarkmail Webmail | 6/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed… | |
| Analizada | Alta (8.2) | 0.55% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke. | |
| Analizada | Media (5.3) | 0.51% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important. | |
| Analizada | Media (5.3) | 0.53% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Analizada | Media (5.3) | 0.53% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass. | |
| Analizada | Media (4.2) | 0.31% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password. | |
| Analizada | Media (6.5) | 0.39% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. | |
| Analizada | Media (6.1) | 0.35% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment. | |
| Analizada | Baja (3.1) | 0.36% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search. | |
| Analizada | Alta (7.5) | 0.60% | — | Roundcube Webmail | 3/4/2026 | 24/7/2026 | An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data. | |
| Analizada | Alta (8.7) | 0.42% | — | Bulwarkmail Webmail | 2/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings… | |
| Analizada | Alta (8.7) | 0.27% | — | Bulwarkmail Webmail | 2/4/2026 | 24/7/2026 | Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in… | |
| Analizada | Alta (7.8) | 0.35% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters. |