Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3270 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. The Id value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying a crafted payload that… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope parameter of /Mondo/lang/sys/Forms/CAL/compose.aspx. The InstanceScope value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldCc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldBcc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesTo value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesBcc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter of /Mobile/Compose.aspx. The Message value is not properly sanitized when processed via a GET request and is reflected into a JavaScript context in the response. By supplying a crafted payload that… | |
| Analizada | Alta (8.5) | 0.19% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAINFY.DLL from its application directo without sufficient integrity validation or secure search order. If the DLL is missing or… | |
| Aplazada | Media (4.3) | 0.21% | — | Webtoffee Decorator-woocommerce-email-customizerAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1. | |
| Aplazada | Media (5.3) | 0.25% | — | Winwar WP Email CaptureAI | 9/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Rhys Wynne WP Email Capture wp-email-capture allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Email Capture: from n/a through <= 3.12.4. | |
| Aplazada | Media (4.3) | 0.29% | — | Elasticemail Elastic Email SenderAI | 9/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elastic Email Sender: from n/a through <= 1.2.20. | |
| Aplazada | Media (4.3) | 0.13% | — | Photoboxone Smtp MailAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in photoboxone SMTP Mail smtp-mail allows Cross Site Request Forgery.This issue affects SMTP Mail: from n/a through <= 1.3.51. | |
| Analizada | Media (5.4) | 0.25% | — | Nextcloud Mail | 5/12/2025 | 17/6/2026 | Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code. | |
| Analizada | Media (6.3) | 0.37% | — | Synology Mail Server | 4/12/2025 | 25/9/2026 | A vulnerability in Synology Mail Server allows remote authenticated attackers to read and write non-sensitive settings, and disable some non-critical functions. | |
| Aplazada | Alta (8.1) | 0.97% | — | SuremailAI | 2/12/2025 | 17/6/2026 | The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1.9.0. This is due to the plugin's save_file() function in inc/emails/handler/uploads.php which duplicates all email attachments to a web-accessible directory… | |
| Aplazada | Alta (7.2) | 0.30% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 2/12/2025 | 17/6/2026 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1.5.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (7.2) | 0.44% | — | Icegram Email Subscribers AND NewslettersAI | 21/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Object Injection.This issue affects Email Subscribers & Newsletters: from n/a through <= 5.9.10. | |
| Analizada | Media (5.3) | 0.33% | — | Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+1 | 20/11/2025 | 17/6/2026 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path. | |
| Analizada | Crítica (9.8) | 0.19% | — | Sonicwall Email Security Appliance 5000 FirmwareSonicwall Email Security Appliance 5050 FirmwareSonicwall Email Security Appliance 7000 FirmwareSonicwall Email Security Appliance 7050 Firmware+1 | 20/11/2025 | 17/6/2026 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution. | |
| Modificada | Media (4.3) | 0.20% | — | Fortinet Fortimail | 18/11/2025 | 17/6/2026 | An improper neutralization of crlf sequences ('crlf injection') vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2 all versions, FortiMail 7.0 all versions may allow an attacker to inject headers in the response via convincing a user to click on a specifically crafted… | |
| Analizada | Media (5.4) | 0.20% | — | Email TFA Project Email TFA | 18/11/2025 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.This issue affects Email TFA: from 0.0.0 before 2.0.6. | |
| Analizada | Baja (1.9) | 0.25% | — | Fabian Email Logging Interface | 15/11/2025 | 7/10/2026 | A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and could be used. | |
| Aplazada | Media (6.5) | 0.23% | — | Codepeople Contact Form TO EmailAI | 13/11/2025 | 7/10/2026 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form Email: from n/a through <= 1.3.58. |