Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.43% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers. | |
| Analizada | Media (6.3) | 0.19% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email. | |
| Analizada | Alta (7.7) | 0.35% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK]. | |
| Analizada | Alta (7.7) | 0.19% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures. | |
| Analizada | Alta (7.8) | 0.48% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. | |
| Analizada | Media (6.3) | 0.37% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. | |
| Analizada | Media (5.3) | 0.31% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject. | |
| Analizada | Media (5.3) | 0.16% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates. | |
| Analizada | Media (5.3) | 0.42% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization. | |
| Analizada | Media (5.3) | 0.38% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions. | |
| Analizada | Media (5.3) | 0.40% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address. | |
| Analizada | Media (6.3) | 0.42% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker with access to a victim's GINA account to bypass a second-password check and read protected emails. | |
| Analizada | Media (4.9) | 0.38% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users. | |
| Analizada | Baja (3.8) | 0.41% | — | Sonicwall Email Security | 31/3/2026 | 24/7/2026 | A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database. | |
| Analizada | Baja (2.7) | 0.47% | — | Sonicwall Email Security | 31/3/2026 | 24/7/2026 | A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive. | |
| Analizada | Media (4.8) | 0.29% | — | Sonicwall Email Security | 31/3/2026 | 24/7/2026 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code. | |
| Analizada | Crítica (9.3) | 0.47% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_supplier.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Modificada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_category.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted… | |
| Analizada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Analizada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a… | |
| Analizada | Media (6.1) | 0.31% | — | Ahsanriaz26gmailcom Sales AND Inventory System | 30/3/2026 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted… |