Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Wisetr User Email Verification FOR Woocommerce | 3/6/2023 | 17/6/2026 | The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to… | |
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa💥 Exploit | Barracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+1 | 24/5/2023 | 17/6/2026 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete… | |
| Modificada | Alta (8.8) | 0.26% | — | Winwar WP Email Capture | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Media (4.3) | 0.37% | — | Jenkins Email Extension | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job. | |
| Modificada | Media (4.3) | 0.50% | — | Jenkins Email Extension | 16/5/2023 | 17/6/2026 | Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system. | |
| Modificada | Media (6.1) | 0.38% | — | I13websolution Mass Email TO Users | 10/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <= 1.1.4 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Winwar WP Email Capture | 2/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Media (4.8) | 0.39% | — | Wpfrom Email Project Wpfrom Email | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPGear.Pro WPFrom Email plugin <= 1.8.8 versions. | |
| Modificada | Media (4.8) | 0.39% | — | WP Better Emails Project WP Better Emails | 20/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 versions. | |
| Modificada | Crítica (9.8) | 0.63% | — | Email Registration Project Email Registration | 6/3/2023 | 16/6/2026 | A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to sql injection. The attack can be initiated remotely. Upgrading to… | |
| Modificada | Media (6.7) | 0.45% | 💥 PoC | Cisco Email Security Appliance | 1/3/2023 | 17/6/2026 | Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A… | |
| Modificada | Alta (7.2) | 1.3% | 💥 PoC | Cisco Email Security ApplianceCisco Secure Email AND WEB Manager | 1/3/2023 | 17/6/2026 | A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user… | |
| Modificada | Crítica (9.9) | 1.1% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields. | |
| Modificada | Media (5.3) | 0.72% | — | Sonicwall Email Security | 14/2/2023 | 17/6/2026 | SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses. | |
| Modificada | Media (6.1) | 0.63% | — | Resend Welcome Email Project Resend Welcome Email | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading… | |
| Modificada | Media (5.4) | 0.65% | — | Cloak Front END Email Project Cloak Front END Email | 6/2/2023 | 17/6/2026 | The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 16/1/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as… | |
| Modificada | Alta (8.8) | 0.91% | — | Smackcoders Visual Email Designer FOR Woocommerce | 2/1/2023 | 17/6/2026 | The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author. | |
| Modificada | Media (5.4) | 0.54% | — | Sangoma Voicemail | 27/12/2022 | 17/6/2026 | A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file views/ssettings.php of the component Settings Handler. The manipulation of the argument key leads to cross site scripting. The attack may be launched remotely. Upgrading to… | |
| Modificada | Media (6.1) | 0.54% | — | Sangoma Voicemail | 27/12/2022 | 17/6/2026 | A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file page.voicemail.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 14.0.6.25 is able to address this… | |
| Modificada | Alta (7.5) | 0.76% | — | Email-existence Project Email-existence | 27/12/2022 | 17/6/2026 | A vulnerability was found in email-existence. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipulation leads to inefficient regular expression complexity. The name of the patch is 0029ba71b6ad0d8ec0baa2ecc6256d038bdd9b56. It is recommended to apply a… | |
| Modificada | Media (6.1) | 0.49% | — | Speakdigital Bulk Delete Users BY Email | 26/12/2022 | 17/6/2026 | The Bulk Delete Users by Email WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (6.5) | 0.33% | — | Speakdigital Bulk Delete Users BY Email | 26/12/2022 | 17/6/2026 | The Bulk Delete Users by Email WordPress plugin through 1.2 does not have CSRF check when deleting users, which could allow attackers to make a logged in admin delete non admin users by knowing their email via a CSRF attack |