Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.23%—Bulwarkmail Webmail6/4/202624/7/2026
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the reverse proxy (proxy.ts) set the Content-Security-Policy-Report-Only header instead of the enforcing Content-Security-Policy header. This means cross-site scripting (XSS) attacks were logged but not blocked. Any user who…
AnalizadaAlta (8.7)0.24%—Bulwarkmail Webmail6/4/202624/7/2026
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed…
AnalizadaAlta (8.2)0.55%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.15 and 1.6.15. The remote image blocking feature can be bypassed via SVG content in an e-mail message. This may lead to information disclosure or access-control bypass. This involves the animate element with attributeName=fill/filter/stroke.
AnalizadaMedia (5.3)0.51%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to a fixed-position mitigation bypass via the use of !important.
AnalizadaMedia (5.3)0.53%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via SVG content (with animate attributes) in an e-mail message. This may lead to information disclosure or access-control bypass.
AnalizadaMedia (5.3)0.53%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed via a crafted background attribute of a BODY element in an e-mail message. This may lead to information disclosure or access-control bypass.
AnalizadaMedia (4.2)0.31%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plugin could lead to type confusion that allows a password change without knowing the old password.
AnalizadaMedia (6.5)0.39%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts.
AnalizadaMedia (6.1)0.35%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachment sanitization in preview mode. A victim must preview a text/html attachment.
AnalizadaBaja (3.1)0.36%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could lead to IMAP injection or CSRF bypass during mail search.
AnalizadaAlta (7.5)0.60%—Roundcube Webmail3/4/202624/7/2026
An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache session handler may lead to arbitrary file write operations by unauthenticated attackers via crafted session data.
AnalizadaAlta (8.7)0.42%—Bulwarkmail Webmail2/4/202624/7/2026
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings…
AnalizadaAlta (8.7)0.27%—Bulwarkmail Webmail2/4/202624/7/2026
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the GET /api/auth/session endpoint previously included the user's plaintext password in the JSON response. This exposed credentials to browser logs, local caches, and network proxie. This issue has been patched in…
AplazadaMedia (4.7)0.53%—Roundcube WebmailAI11/2/202617/6/2026
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13 allows Cascading Style Sheets (CSS) injection, e.g., because comments are mishandled.
AplazadaMedia (4.3)0.48%💥 PoCRoundcube WebmailAI9/2/202617/6/2026
Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not block SVG feImage.
AnalizadaMedia (6.1)27%⚠ Explotación activa💥 PoCRoundcube Webmail18/12/202517/6/2026
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
AnalizadaAlta (7.5)0.28%—Roundcube Webmail18/12/202517/6/2026
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a information disclosure vulnerability in the HTML style sanitizer.
AplazadaMedia (4.3)0.34%💥 PoCSogo WebmailAI4/8/202517/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in SOGo Webmail thru 5.6.0, allowing an authenticated user to send emails on behalf of other users by manipulating a user-controlled identifier in the email-sending request. The server fails to verify whether the authenticated user is authorized…
AnalizadaAlta (8.8)99%⚠ Explotación activa💥 ExploitRoundcube WebmailDebian Linux2/6/202517/6/2026
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
AnalizadaMedia (6.1)29%—Roundcube Webmail3/2/202517/6/2026
Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.
AnalizadaCrítica (9.3)83%⚠ Explotación activa💥 ExploitRoundcube Webmail5/8/202417/6/2026
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.
ModificadaCrítica (9.3)34%💥 PoCRoundcube Webmail5/8/202417/6/2026
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
AnalizadaCrítica (9.8)1.5%—Roundcube Webmail7/6/202417/6/2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.
AnalizadaMedia (6.1)0.50%—Roundcube WebmailDebian Linux7/6/202417/6/2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
AnalizadaMedia (6.1)73%⚠ Explotación activa💥 ExploitRoundcube WebmailDebian Linux7/6/202417/6/2026
Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
Orbitaley — Vulnerabilidades