Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.92%—K-9 Mail Project K-9 Mail7/4/201917/6/2026
K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain…
ModificadaAlta (7.4)1.2%—Django-anymail Project Django-anymail13/3/201817/6/2026
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports,…
ModificadaCrítica (9.1)2.6%—Django-anymail Project Django-anymailDebian Linux3/2/201817/6/2026
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
ModificadaMedia (6.1)3.4%—Mail Project Mail12/6/201717/6/2026
The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.
ModificadaAlta (7.8)0.39%—Firejail Project Firejail13/4/201717/6/2026
Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.
ModificadaAlta (7.8)0.39%—Firejail Project Firejail13/4/201717/6/2026
Firejail does not properly clean environment variables, which allows local users to gain privileges.
ModificadaAlta (7.8)0.39%—Firejail Project Firejail13/4/201717/6/2026
Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.
ModificadaAlta (7.8)0.39%—Firejail Project Firejail13/4/201717/6/2026
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.
ModificadaAlta (7.8)0.39%—Firejail Project Firejail13/4/201717/6/2026
Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.
ModificadaBaja (3.3)0.33%—Firejail Project Firejail13/4/201717/6/2026
Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.
ModificadaAlta (7.8)0.39%—Firejail Project Firejail13/4/201717/6/2026
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
ModificadaAlta (7)1.0%💥 ExploitS-nail Project S-nail27/3/201717/6/2026
Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
ModificadaAlta (7.8)0.40%—Firejail Project Firejail23/3/201717/6/2026
Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument.
ModificadaCrítica (9)1.9%—Firejail Project Firejail23/3/201717/6/2026
Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
ModificadaMedia (6.1)0.96%—WP Mail Project WP Mail10/2/201717/6/2026
An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail.
ModificadaAlta (8.8)0.36%—Firejail Project Firejail9/2/201717/6/2026
Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this…
ModificadaAlta (8.8)0.74%💥 ExploitFirejail Project Firejail9/2/201717/6/2026
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option.
ModificadaAlta (8.8)0.35%—Firejail Project Firejail19/1/201717/6/2026
Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
ModificadaMedia (6.1)3.5%💥 ExploitPondol-formmail Project Pondol-formmail10/10/201617/6/2026
Reflected XSS in wordpress plugin pondol-formmail v1.1
ModificadaBaja (3.5)0.91%—Workbench Email Project Workbench Email17/9/201517/6/2026
The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node.
ModificadaMedia (4.3)3.7%💥 ExploitWP Simplemail Project WP Simplemail20/6/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.
ModificadaMedia (4.3)1.8%—Basic Webmail Project Basic WebmailJason Flatt Basic Webmail3/12/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message.
ModificadaMedia (4.3)0.90%—Hypermail-project Hypermail14/1/201116/6/2026
Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted From address, which is not properly handled when indexing messages.
ModificadaCrítica (9.8)11%—Qmail Project QmailCanonical Ubuntu LinuxDebian Linux11/5/200516/6/2026
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.
ModificadaBaja (2.1)1.3%💥 ExploitQmail Project Qmail1/6/199716/6/2026
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.
Orbitaley — Vulnerabilidades