Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.33% | 💥 PoC | Axigen Mail Server | 5/2/2026 | 17/6/2026 | Axigen Mail Server before 10.5.57 contains an improper access control vulnerability in the WebAdmin interface. A delegated admin account with zero permissions can bypass access control checks and gain unauthorized access to the SSL Certificates management endpoint (page=sslcerts). This allows the attacker to view,… | |
| Analizada | Media (5.1) | 0.49% | — | Torchbox Wagtail | 4/2/2026 | 17/6/2026 | Wagtail is an open source content management system built on Django. Prior to versions 6.3.6, 7.0.4, 7.1.3, 7.2.2, and 7.3, due to a missing permission check on the preview endpoints, a user with access to the Wagtail admin and knowledge of a model's fields can craft a form submission to obtain a preview rendering of… | |
| Aplazada | Media (5.4) | 0.19% | — | Mail MintAI | 3/2/2026 | 17/6/2026 | The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19.2. This is due to missing nonce validation on the create_or_update_note function. This makes it possible for unauthenticated attackers to create or update contact notes via a forged request granted… | |
| Aplazada | Crítica (9.2) | 5.5% | 💥 Exploit | Ruby-vips Image ProcessingAIImagemagick Mini MagickAIRubyonrails Active StorageAI | 30/1/2026 | 15/7/2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three methods allow for the circumvention of the safe defaults which enables potential command… | |
| Analizada | Media (6.9) | 0.31% | — | Smartertools Smartermail | 29/1/2026 | 17/6/2026 | SmarterTools SmarterMail versions prior to build 9518 contain an unauthenticated path coercion vulnerability in the background-of-the-day preview endpoint. The application base64-decodes attacker-supplied input and uses it as a filesystem path without validation. On Windows systems, this allows UNC paths to be… | |
| Analizada | Media (5.4) | 0.23% | — | Remyandrade Domain Availability Checker | 23/1/2026 | 17/6/2026 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML… | |
| Analizada | Crítica (9.3) | 88% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 23/1/2026 | 4/8/2026 | SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be executed by the vulnerable application. | |
| Aplazada | Media (6) | 0.58% | — | Python Email ModuleAI | 23/1/2026 | 17/6/2026 | The email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new… | |
| Aplazada | Media (4.3) | 0.15% | — | Marynixie Related Posts ThumbnailsAI | 23/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in marynixie Related Posts Thumbnails Plugin for WordPress related-posts-thumbnails allows Cross Site Request Forgery.This issue affects Related Posts Thumbnails Plugin for WordPress: from n/a through <= 4.3.2. | |
| Aplazada | Media (4.3) | 0.23% | — | Mkscripts Download After EmailAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download After Email: from n/a through <= 2.1.9. | |
| Aplazada | Media (6.5) | 0.23% | — | Steve Truman Woocommerce Email Inquiry Cart OptionsAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Steve Truman Email Inquiry & Cart Options for WooCommerce woocommerce-email-inquiry-cart-options allows DOM-Based XSS.This issue affects Email Inquiry & Cart Options for WooCommerce: from n/a through <= 3.5.0. | |
| Aplazada | Media (4.3) | 0.15% | — | Timur Kamaev Kama ThumbnailAI | 23/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Timur Kamaev Kama Thumbnail kama-thumbnail allows Cross Site Request Forgery.This issue affects Kama Thumbnail: from n/a through <= 3.5.1. | |
| Aplazada | Alta (7.1) | 0.26% | — | Boopathirajan WP Test EmailAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Boopathi Rajan WP Test Email wp-test-email allows Reflected XSS.This issue affects WP Test Email: from n/a through <= 1.1.7. | |
| Aplazada | Alta (8.1) | 0.58% | — | Ancorathemes TailsAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Tails tails allows PHP Local File Inclusion.This issue affects Tails: from n/a through <= 1.4.12. | |
| Aplazada | Alta (8.1) | 0.58% | — | Goalthemes BaillyAI | 22/1/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allows PHP Local File Inclusion.This issue affects Bailly: from n/a through <= 1.3.4. | |
| Aplazada | Alta (7.5) | 0.37% | — | Antideo Email ValidatorAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Antideo Antideo Email Validator antideo-email-validator allows Blind SQL Injection.This issue affects Antideo Email Validator: from n/a through <= 1.0.10. | |
| Aplazada | Alta (7.1) | 0.27% | — | Mndpsingh287 WP MailAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mndpsingh287 WP Mail wp-mail allows Reflected XSS.This issue affects WP Mail: from n/a through <= 1.3. | |
| Aplazada | Crítica (9.3) | 0.43% | — | WOO MailerliteAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MailerLite MailerLite – WooCommerce integration woo-mailerlite allows SQL Injection.This issue affects MailerLite – WooCommerce integration: from n/a through <= 3.1.2. | |
| Analizada | Crítica (9.3) | 97% | ⚠ Explotación activa💥 Exploit | Smartertools Smartermail | 22/1/2026 | 4/8/2026 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts. An unauthenticated… | |
| Analizada | Media (6.1) | 0.20% | 💥 PoC | Abacre Retail Point OF Sale | 20/1/2026 | 17/6/2026 | Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients module. The application fails to properly sanitize user-supplied input stored in the Name and Surname fields. An attacker can insert malicious HTML or script content into these fields, which,… | |
| Analizada | Media (6.5) | 0.21% | 💥 PoC | Abacre Retail Point OF Sale | 20/1/2026 | 17/6/2026 | Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in the Search function of the Orders page. | |
| Aplazada | Media (5.3) | 0.31% | — | Wedevs WemailAI | 20/1/2026 | 17/6/2026 | The weMail - Email Marketing, Lead Generation, Optin Forms, Email Newsletters, A/B Testing, and Automation plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.7. This is due to the plugin's REST API trusting the `x-wemail-user` HTTP header to identify users without… | |
| Analizada | Alta (7.5) | 0.44% | — | Axllent Mailpit | 19/1/2026 | 17/6/2026 | Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request Forgery (SSRF) via HTML Check CSS Download. The HTML Check feature (`/api/v1/message/{ID}/html-check`) is designed to analyze HTML emails for compatibility. During this process, the… | |
| Analizada | Media (5.3) | 1.4% | 💥 Exploit | Axllent Mailpit | 19/1/2026 | 17/6/2026 | Mailpit is an email testing tool and API for developers. Prior to version 1.28.3, Mailpit's SMTP server is vulnerable to Header Injection due to an insufficient Regular Expression used to validate `RCPT TO` and `MAIL FROM` addresses. An attacker can inject arbitrary SMTP headers (or corrupt existing ones) by including… | |
| Aplazada | Media (4.4) | 0.30% | — | CM Email BlacklistAI | 17/1/2026 | 17/6/2026 | The CM E-Mail Blacklist – Simple email filtering for safer registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'black_email' parameter in all versions up to, and including, 1.6.2. This is due to insufficient input sanitization and output escaping. This makes it possible for… |