Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.37% | — | Directorytree ImapengineAI | 14/2/2026 | 17/6/2026 | Versions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the id() function in ImapConnection.php due to improperly escaping user input before including it in IMAP ID commands. This allows… | |
| Aplazada | Media (5.9) | 0.42% | — | Python ImaplibAI | 20/1/2026 | 6/8/2026 | The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters. | |
| Aplazada | Media (5.9) | 0.22% | — | Imaprogrammer Custom CommentAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imaprogrammer Custom Comment customcomment allows Stored XSS.This issue affects Custom Comment: from n/a through <= 2.1.6. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Opensuse Cyrus-imapdAI | 26/5/2025 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed cyrus-imapd allows escalation from cyrus to root.This issue affects openSUSE Tumbleweed cyrus-imapd before 3.8.4-2.1. | |
| Aplazada | Media (6.5) | 0.63% | — | Ruby Net-imapAI | 10/2/2025 | 17/6/2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Starting in version 0.3.2 and prior to versions 0.3.8, 0.4.19, and 0.5.6, there is a possibility for denial of service by memory exhaustion in `net-imap`'s response parser. At any time while the client is connected, a malicious… | |
| Aplazada | Alta (7.1) | 0.43% | — | Imsoftware WP Imap AuthAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in imsoftware WP IMAP Auth wp-imap-authentication allows Reflected XSS.This issue affects WP IMAP Auth: from n/a through <= 4.0.1. | |
| Analizada | Alta (8.8) | 1.1% | — | Fortinet Fortisoar Imap Connector | 14/1/2025 | 17/6/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted playbook | |
| Modificada | Media (6.5) | 0.84% | — | Cyrusimap Cyrus Imap | 5/6/2024 | 17/6/2026 | Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation by sending many LITERALs in a single command. | |
| Modificada | Media (5.9) | 0.80% | — | Apache AirflowApache-airflow-providers-imapApache-airflow-providers-smtp | 23/8/2023 | 17/6/2026 | Apache Airflow SMTP Provider before 1.3.0, Apache Airflow IMAP Provider before 3.3.0, and Apache Airflow before 2.7.0 are affected by the Validation of OpenSSL Certificate vulnerability. The default SSL context with SSL library did not check a server's X.509 certificate. Instead, the code accepted any certificate,… | |
| Modificada | Crítica (9.8) | 3.2% | — | Webklex Php-imap | 23/6/2023 | 17/6/2026 | PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Prior to version 5.3.0, an unsanitized attachment filename allows any unauthenticated user to leverage a directory traversal vulnerability, which results in a remote code execution vulnerability. Every… | |
| Modificada | Media (6.5) | 0.63% | — | Imapsync Project Imapsync | 30/5/2023 | 17/6/2026 | imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, and thus (for example) an attacker can modify imapsync's cache and overwrite files belonging to the user who runs it. | |
| Modificada | Alta (8.8) | 4.1% | — | Cyrusimap Cyrus-saslDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+4 | 24/2/2022 | 17/6/2026 | In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. | |
| Modificada | Alta (7.5) | 3.1% | — | Cyrus ImapFedoraproject FedoraDebian Linux | 1/9/2021 | 17/6/2026 | Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16. | |
| Modificada | Media (4.3) | 1.7% | — | Cyrus ImapFedoraproject Fedora | 10/5/2021 | 17/6/2026 | Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall. | |
| Modificada | Alta (7.4) | 0.77% | — | Em-imap Project Em-imap | 19/5/2020 | 17/6/2026 | em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. | |
| Modificada | Alta (7.5) | 8.0% | — | Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+15 | 19/12/2019 | 17/6/2026 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. | |
| Modificada | Media (6.5) | 1.7% | — | Cyrus ImapDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 16/12/2019 | 17/6/2026 | An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox… | |
| Modificada | Crítica (9.8) | 2.4% | — | Cyrus ImapFedoraproject FedoraDebian Linux | 15/11/2019 | 17/6/2026 | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection. | |
| Modificada | Crítica (9.8) | 1.0% | — | Debian LinuxOfflineimap | 13/11/2019 | 16/6/2026 | offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies. | |
| Modificada | Media (5.9) | 0.63% | — | Debian LinuxOfflineimap | 13/11/2019 | 16/6/2026 | offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks. | |
| Modificada | Alta (7.5) | 0.95% | — | Imapfilter Project ImapfilterDebian LinuxFedoraproject FedoraOpensuse Backports SLE+1 | 8/9/2019 | 17/6/2026 | IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. | |
| Modificada | Crítica (9.8) | 7.6% | — | Cyrus ImapFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+4 | 3/6/2019 | 17/6/2026 | The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name. | |
| Modificada | Alta (7.5) | 96% | 💥 Exploit | PHPDebian LinuxUw-imap Project Uw-imapCanonical Ubuntu Linux | 25/11/2018 | 17/6/2026 | University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to… | |
| Modificada | Media (6.1) | 1.0% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.5% | — | NEO Debun ImapNEO Debun POP | 15/11/2018 | 17/6/2026 | Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any executable files via unspecified vectors. |