Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.92% | — | K-9 Mail Project K-9 Mail | 7/4/2019 | 17/6/2026 | K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an attacker to obtain… | |
| Modificada | Alta (7.4) | 1.2% | — | Django-anymail Project Django-anymail | 13/3/2018 | 17/6/2026 | Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports,… | |
| Modificada | Crítica (9.1) | 2.6% | — | Django-anymail Project Django-anymailDebian Linux | 3/2/2018 | 17/6/2026 | webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events. | |
| Modificada | Media (6.1) | 3.4% | — | Mail Project Mail | 12/6/2017 | 17/6/2026 | The mail gem before 2.5.5 for Ruby (aka A Really Ruby Mail Library) is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring. | |
| Modificada | Alta (7.8) | 0.39% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. | |
| Modificada | Alta (7.8) | 0.39% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail does not properly clean environment variables, which allows local users to gain privileges. | |
| Modificada | Alta (7.8) | 0.39% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges. | |
| Modificada | Alta (7.8) | 0.39% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges. | |
| Modificada | Alta (7.8) | 0.39% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. | |
| Modificada | Baja (3.3) | 0.33% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /. | |
| Modificada | Alta (7.8) | 0.39% | — | Firejail Project Firejail | 13/4/2017 | 17/6/2026 | Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc. | |
| Modificada | Alta (7) | 1.0% | 💥 Exploit | S-nail Project S-nail | 27/3/2017 | 17/6/2026 | Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument. | |
| Modificada | Alta (7.8) | 0.40% | — | Firejail Project Firejail | 23/3/2017 | 17/6/2026 | Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument. | |
| Modificada | Crítica (9) | 1.9% | — | Firejail Project Firejail | 23/3/2017 | 17/6/2026 | Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument. | |
| Modificada | Media (6.1) | 0.96% | — | WP Mail Project WP Mail | 10/2/2017 | 17/6/2026 | An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail. | |
| Modificada | Alta (8.8) | 0.36% | — | Firejail Project Firejail | 9/2/2017 | 17/6/2026 | Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this… | |
| Modificada | Alta (8.8) | 0.74% | 💥 Exploit | Firejail Project Firejail | 9/2/2017 | 17/6/2026 | Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. | |
| Modificada | Alta (8.8) | 0.35% | — | Firejail Project Firejail | 19/1/2017 | 17/6/2026 | Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. | |
| Modificada | Media (6.1) | 3.5% | 💥 Exploit | Pondol-formmail Project Pondol-formmail | 10/10/2016 | 17/6/2026 | Reflected XSS in wordpress plugin pondol-formmail v1.1 | |
| Modificada | Baja (3.5) | 0.91% | — | Workbench Email Project Workbench Email | 17/9/2015 | 17/6/2026 | The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | WP Simplemail Project WP Simplemail | 20/6/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email. | |
| Modificada | Media (4.3) | 1.8% | — | Basic Webmail Project Basic WebmailJason Flatt Basic Webmail | 3/12/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via a (1) page title or (2) crafted email message. | |
| Modificada | Media (4.3) | 0.90% | — | Hypermail-project Hypermail | 14/1/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hypermail 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted From address, which is not properly handled when indexing messages. | |
| Modificada | Crítica (9.8) | 11% | — | Qmail Project QmailCanonical Ubuntu LinuxDebian Linux | 11/5/2005 | 16/6/2026 | Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request. | |
| Modificada | Baja (2.1) | 1.3% | 💥 Exploit | Qmail Project Qmail | 1/6/1997 | 16/6/2026 | Denial of service in Qmail by specifying a large number of recipients with the RCPT command. |