Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

4604 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.27%—Hide Email AddressAI12/12/20257/10/2026
El plugin Hide Email Address para WordPress es vulnerable a cross-site scripting almacenado a través del parámetro 'inline_css' en el shortcode 'bg-hide-email-address' en todas las versiones hasta la 0.1, inclusive, debido a una sanitización de entrada y un escape de salida insuficientes en atributos proporcionados…
AplazadaAlta (8.6)0.54%—FOF Pretty MailAI11/12/202517/6/2026
FoF Pretty Mail 1.1.2 contains a server-side template injection vulnerability that allows administrative users to inject malicious code into email templates. Attackers can execute system commands by inserting crafted template expressions that trigger arbitrary code execution during email generation.
AplazadaMedia (6.9)0.34%—FOF Pretty MailAI11/12/202517/6/2026
FoF Pretty Mail 1.1.2 contains a local file inclusion vulnerability that allows administrative users to include arbitrary server files in email templates. Attackers can exploit the template settings by inserting file inclusion payloads to read sensitive system files like /etc/passwd during email generation.
AnalizadaAlta (8.4)0.12%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.SAV with overly permissive filesystem access. A local authenticated user with read…
AnalizadaAlta (8.4)0.12%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local credential compromise and account takeover. The product stores user and administrative passwords in plaintext within AUTH.TAB with overly permissive filesystem access. A local authenticated user with read…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIDP.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIPC.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.20%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISP.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIAM.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISM.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIMF.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAISO.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202517/6/2026
MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code execution. The MailEnable administrative executable attempts to load MEAIPO.DLL from its installation directory without sufficient integrity validation or a secure search order. A local attacker with…
AnalizadaAlta (8.5)0.17%—Mailenable10/12/202525/9/2026
Versiones de MailEnable anteriores a la 10.54 contienen una vulnerabilidad de carga de DLL insegura que puede conducir a la ejecución de código arbitrario local. El ejecutable administrativo de MailEnable intenta cargar MEAIAU.DLL desde su directorio de instalación sin suficiente validación de integridad o un orden de…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202525/9/2026
MailEnable versiones anteriores a 10.54 contienen una vulnerabilidad de cross-site scripting (XSS) reflejado en el parámetro WindowContext de /Mondo/lang/sys/Forms/MAI/compose.aspx. El valor de WindowContext no se depura correctamente cuando se procesa a través de una solicitud GET y se refleja dentro de un contexto…
AnalizadaMedia (5.3)0.49%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Failed parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Failed value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out…
AnalizadaMedia (5.3)0.49%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Added parameter of /Mondo/lang/sys/Forms/MAI/AddRecipientsResult.aspx. The Added value is not properly sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of…
AnalizadaMedia (5.3)0.49%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the theme parameter of /Mondo/lang/sys/Forms/Statistics.aspx. The theme value is insufficiently sanitized when processed via a GET request and is reflected in the response, allowing an attacker to break out of an…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Id parameter of /Mobile/ContactDetails.aspx. The Id value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying a crafted payload that…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the InstanceScope parameter of /Mondo/lang/sys/Forms/CAL/compose.aspx. The InstanceScope value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldTo value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldCc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the FieldBcc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The FieldBcc value is not properly sanitized when processed via a GET request and is reflected inside a <script> block in the JavaScript variable var…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesTo parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesTo value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the response. By supplying…
AnalizadaMedia (5.3)0.40%—Mailenable9/12/202517/6/2026
MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc parameter of /Mondo/lang/sys/Forms/AddressBook.aspx. The AddressesCc value is not properly sanitized when processed via a GET request and is reflected within a <script> block in the JavaScript variable…