Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

893 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.73%—Siemens Mendix Email Connector13/12/202217/6/2026
A vulnerability has been identified in Mendix Email Connector (All versions < V2.0.0). Affected versions of the module improperly handle access control for some module entities. This could allow authenticated remote attackers to read and manipulate sensitive information.
ModificadaAlta (8.8)0.76%—Icegram Email Subscribers & Newsletters12/12/202217/6/2026
The Icegram Express WordPress plugin before 5.5.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by any authenticated users, such as subscriber
ModificadaAlta (7.5)0.62%—Interspire Email Marketer9/12/202217/6/2026
Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could successfully perform an attack to extract potentially sensitive information from the database if the survey id exists.
ModificadaAlta (7.5)0.83%—Cisco Email Security Appliance4/11/202217/6/2026
A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain TLS connections that are processed by an affected device. An…
ModificadaMedia (5.3)0.58%—Cisco Email Security Appliance FirmwareCisco Secure Email AND WEB Manager Firmware4/11/202217/6/2026
A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its environment to properly sanitize input values. An attacker…
ModificadaAlta (7.2)1.3%—Kadencewp Kadence Woocommerce Email Designer25/10/202217/6/2026
The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
ModificadaAlta (8.8)0.93%—Interspire Email Marketer11/10/202217/6/2026
Interspire Email Marketer through 6.5.0 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a /admin/temp/surveys/ URI. NOTE: this issue exists because of an incomplete fix for CVE-2018-19550.
ModificadaCrítica (9.8)0.81%—Forcepoint Cloud Security GatewayForcepoint Data Loss PreventionForcepoint Email SecurityForcepoint ONE Endpoint With Policy Engine+112/9/202217/6/2026
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), Web Security Content Gateway, Email Security with DLP enabled, and Cloud Security Gateway prior to June 20, 2022. The XML…
ModificadaAlta (7.8)0.19%—Samsung Email9/9/202217/6/2026
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
ModificadaMedia (5.4)0.55%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter. after login leads to inject malicious tag leads to IFRAME injection.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoint.
ModificadaCrítica (9.8)1.4%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
ModificadaMedia (5.4)0.61%—Altn Security Gateway FOR Email Servers25/8/202217/6/2026
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
ModificadaMedia (5.5)0.20%—Samsung Email5/8/202217/6/2026
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.
AnalizadaAlta (7.5)0.62%—Sonicwall Hosted Email Security29/7/202217/6/2026
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions
ModificadaMedia (5.4)0.64%—Jenkins Validating Email Parameter30/6/202217/6/2026
Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaMedia (4.8)0.59%—Miniorange Login With OTP Over Sms, Email, Whatsapp AND Google Authenticator27/6/202217/6/2026
The Login With OTP Over SMS, Email, WhatsApp and Google Authenticator WordPress plugin before 1.0.8 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
ModificadaMedia (6.5)0.53%—Wp-email Project Wp-email20/6/202217/6/2026
The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack
ModificadaAlta (7.5)1.2%—Wp-email Project Wp-email20/6/202217/6/2026
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
ModificadaMedia (4.8)0.59%—Print, Pdf, Email BY Printfriendly20/6/202217/6/2026
The Print, PDF, Email by PrintFriendly WordPress plugin before 5.2.3 does not sanitise and escape the Custom Button Text settings, which could allow high privilege users such as admin to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaCrítica (9.8)1.5%—Cisco Email Security ApplianceCisco Secure Email AND WEB Manager15/6/202217/6/2026
A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface…
Orbitaley — Vulnerabilidades