Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
893 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 1.0% | — | Cisco Email Security ApplianceCisco Secure Email AND WEB Manager | 15/6/2022 | 17/6/2026 | A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Protocol (LDAP)… | |
| Modificada | Media (6.5) | 0.53% | — | NEW User Email SET UP Project NEW User Email SET UP | 13/6/2022 | 17/6/2026 | The New User Email Set Up WordPress plugin through 0.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.5) | 0.53% | — | Email Users Project Email Users | 13/6/2022 | 17/6/2026 | The Email Users WordPress plugin through 4.8.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and change the notification settings of arbitrary users | |
| Modificada | Media (5.4) | 0.61% | — | Cisco Enterprise Chat AND Email | 27/5/2022 | 17/6/2026 | A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input that is processed by the web interface.… | |
| Modificada | Media (6.1) | 0.79% | — | Wpchill Check & LOG Email | 23/5/2022 | 17/6/2026 | The Check & Log Email WordPress plugin before 1.0.6 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.3) | 0.69% | — | Menlosecurity Email Isolation | 2/5/2022 | 17/6/2026 | Links may not be rewritten according to policy in some specially formatted emails. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 Exploit | Speakout! Email Petitions Project Speakout! Email Petitions | 28/3/2022 | 17/6/2026 | The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before using it in a SQL statement via the dk_speakout_sendmail AJAX action, leading to an SQL Injection exploitable by unauthenticated users | |
| Modificada | Media (4.9) | 0.81% | — | Mimecast Email Security | 16/3/2022 | 17/6/2026 | Mimecast Email Security before 2020-01-10 allows any admin to spoof any domain, and pass DMARC alignment via SPF. This occurs through misuse of the address rewrite feature. (The domain being spoofed must be a customer in the Mimecast grid from which the spoofing occurs.) | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Techspawn Wp-email-users | 14/3/2022 | 17/6/2026 | The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJAX action, available to any authenticated users, allowing them to perform SQL injection attacks. | |
| Modificada | Alta (7.3) | 0.74% | — | F-secure Client SecurityF-secure CounterceptF-secure ElementsF-secure Email AND Server Security+1 | 10/3/2022 | 17/6/2026 | An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands. | |
| Modificada | Alta (8.8) | 4.2% | 💥 Exploit | Icegram Email Subscribers & Newsletters | 7/3/2022 | 17/6/2026 | The Email Subscribers & Newsletters WordPress plugin before 5.3.2 does not correctly escape the `order` and `orderby` parameters to the `ajax_fetch_report_list` action, making it vulnerable to blind SQL injection attacks by users with roles as low as Subscriber. Further, it does not have any CSRF protection in place… | |
| Modificada | Media (4.3) | 0.43% | — | Madewithfuel Customize Wordpress Emails AND Alerts | 28/2/2022 | 17/6/2026 | The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have authorisation and CSRF check in its bnfw_search_users AJAX action, allowing any authenticated users to call it and query for user e-mail prefixes (finding the first letter, then the second one, then the third one etc.). | |
| Modificada | Media (6.1) | 0.80% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 14/2/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 71% | 💥 Exploit | Codemiq Wordpress Email Template Designer | 4/2/2022 | 17/6/2026 | The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9.… | |
| Modificada | Media (6.5) | 0.86% | — | Microfocus Voltage Securemail | 4/2/2022 | 17/6/2026 | A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Relay prior to 7.3.0.1. The vulnerability could be exploited to create an information leakage attack. | |
| Modificada | Media (6.1) | 0.81% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 24/1/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (4.3) | 0.39% | — | Email Tracker Project Email Tracker | 19/1/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email Tracker WordPress plugin (versions <= 5.2.6). | |
| Modificada | Media (4.6) | 0.24% | — | Samsung Email | 10/1/2022 | 17/6/2026 | Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox. | |
| Modificada | Media (5.9) | 100% | 💥 PoC | Apache Log4jNetapp Cloud ManagerDebian LinuxSonicwall Email Security+112 | 18/12/2021 | 25/8/2026 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Apache Log4jCvat Computer Vision Annotation ToolIntel Audio Development KITIntel Datacenter Manager+51 | 14/12/2021 | 17/6/2026 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example,… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 0.83% | — | Email LOG Project Email LOG | 6/12/2021 | 17/6/2026 | The Email Log WordPress plugin before 2.4.8 does not escape the d parameter before outputting it back in an attribute in the Log page, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.1) | 0.78% | — | Wpchill Check & LOG Email | 29/11/2021 | 17/6/2026 | The Check & Log Email WordPress plugin before 1.0.4 does not escape the d parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 1.4% | — | Mandsconsulting Email Before Download | 29/11/2021 | 17/6/2026 | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues | |
| Modificada | Media (4.8) | 0.62% | — | Codepeople Contact Form Email | 17/11/2021 | 17/6/2026 | The Contact Form Email WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and escaping via the name parameter found in the ~/trunk/cp-admin-int-list.inc.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to… |