Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
896 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.19% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-separated domain atoms to be retained in the normalized address. For… | |
| Aplazada | Alta (7.6) | 0.29% | — | Email LOGAI | 23/9/2026 | 23/9/2026 | Administrator SQL Injection in Email Log <= 2.63 versions. | |
| Aplazada | Media (5.3) | 0.22% | — | Email SubscribersAI | 23/9/2026 | 23/9/2026 | The Email Subscribers & Newsletters WordPress plugin before 5.9.35 does not verify the per-subscriber management token before changing a subscriber's subscription status, allowing unauthenticated users to force-unsubscribe or force-confirm an arbitrary subscriber whose email address they know. | |
| Aplazada | Crítica (9.8) | 0.60% | — | Perl Email-senderAI | 21/9/2026 | 22/9/2026 | Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other… | |
| Aplazada | Crítica (9.8) | 0.32% | — | Maildata Email Archiving SystemAI | 17/9/2026 | 22/9/2026 | In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists. | |
| Aplazada | Baja (2.1) | 0.84% | — | Punchin-emailAICloudflare WorkersAI | 17/9/2026 | 30/9/2026 | punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent… | |
| Pendiente de análisis | Alta (8.3) | 0.40% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain… | |
| Pendiente de análisis | Alta (8.3) | 0.38% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the… | |
| Pendiente de análisis | Alta (8.7) | 0.82% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for… | |
| Pendiente de análisis | Media (6) | 0.29% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key,… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 16/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.62% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Aplazada | Media (6.9) | 0.76% | — | Simalexan Api-lambda-send-email-sesAI | 13/9/2026 | 14/9/2026 | A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | NodemailerAI | 13/9/2026 | 24/9/2026 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several… | |
| Aplazada | Alta (7.1) | 0.40% | — | Mailmunch Grow Your Email ListAI | 10/9/2026 | 10/9/2026 | Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions. | |
| Pendiente de análisis | Crítica (9.9) | 0.86% | 💥 PoC | CpanelAICpanel EmailtrackAI | 9/9/2026 | 10/9/2026 | A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component | |
| Analizada | Media (4.8) | 0.08% | — | Samsung Visual Voicemail | 9/9/2026 | 23/9/2026 | Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission. | |
| Aplazada | Media (6.5) | 0.33% | — | Blog Studio Email Subscribers AND NewslettersAI | 7/9/2026 | 8/9/2026 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly… | |
| Aplazada | Alta (8.6) | 0.64% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 4/9/2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |
| Aplazada | Alta (7.7) | 0.47% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor. | |
| Aplazada | Alta (8.6) | 1.2% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | Cisco Secure EmailAI | 2/9/2026 | 2/9/2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An… |