Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
4604 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.27% | — | Hide Email AddressAI | 12/12/2025 | 7/10/2026 | El plugin Hide Email Address para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'inline_css' en el shortcode 'bg-hide-email-address' en todas las versiones hasta la 0.1, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en atributos proporcionados… | |
| Aplazada | Alta (8.6) | 0.54% | — | FOF Pretty MailAI | 11/12/2025 | 17/6/2026 | FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation. | |
| Aplazada | Media (6.9) | 0.34% | — | FOF Pretty MailAI | 11/12/2025 | 17/6/2026 | FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrary server files in email templates. Attackers can exploit the template settings by inserting file inclusion payloads to read sensitive system files like /etc/passwd during email generation. | |
| Analizada | Alta (8.4) | 0.12% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.SAV with overly permissive filesystem access. A local authenticated user with read… | |
| Analizada | Alta (8.4) | 0.12% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.TAB with overly permissive filesystem access. A local authenticated user with read… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIDP.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIPC.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.20% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISP.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIAM.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISM.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIMF.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISO.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIPO.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with… | |
| Analizada | Alta (8.5) | 0.17% | — | Mailenable | 10/12/2025 | 25/9/2026 | Versiones de MailEnable anteriores a la 10.54 contienen una vulnerabilidad de carga de DLL insegura que puede conducir a la ejecución de código arbitrario local. El ejecutable administrativo de MailEnable intenta cargar MEAIAU.DLL desde su directorio de instalación sin suficiente validación de integridad o un orden de… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 25/9/2026 | MailEnable versiones anteriores a 10.54 contienen una vulnerabilidad de cross-site scripting (XSS) reflejado en el parámetro WindowContext de /Mondo/lang/sys/Forms/MAI/compose.aspx. El valor de WindowContext no se depura correctamente cuando se procesa a través de una solicitud GET y se refleja dentro de un contexto… | |
| Analizada | Media (5.3) | 0.49% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Failed value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out… | |
| Analizada | Media (5.3) | 0.49% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Added value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of… | |
| Analizada | Media (5.3) | 0.49% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter of /Mondo/lang/sys/Forms/Statistics.aspx. The theme value is insufficiently sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of an… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. The Id value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying a crafted payload that… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope parameter of /Mondo/lang/sys/Forms/CAL/compose.aspx. The InstanceScope value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldCc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldBcc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesTo value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying… | |
| Analizada | Media (5.3) | 0.40% | — | Mailenable | 9/12/2025 | 17/6/2026 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable… |