Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

896 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.9)0.16%—Cisco Secure EmailAI2/9/20262/9/2026
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An…
AplazadaAlta (7.1)0.25%—Email EssentialsAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
AplazadaAlta (7.1)0.25%—Email Subscribers AND NewslettersAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
Pendiente de análisisCrítica (9.3)2.0%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without…
Pendiente de análisisMedia (6.9)1.0%—NodemailerAI31/8/202610/9/2026
Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for…
Pendiente de análisisAlta (8.3)0.19%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised…
Pendiente de análisisMedia (5.3)0.26%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail…
Pendiente de análisisMedia (5.3)0.26%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.
Pendiente de análisisAlta (7.1)0.35%—NodemailerAI31/8/202610/9/2026
nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or…
Pendiente de análisisMedia (6.9)0.30%—NodemailerAI31/8/202610/9/2026
nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny…
AplazadaMedia (5.1)0.44%—Watchguard Dimension Email ServerAI28/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.
Pendiente de análisisMedia (5.7)0.19%—Drupal Email Login OTPAI25/8/202628/8/2026
Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.
AplazadaAlta (8.7)0.66%—Getgrav Grav-plugin-emailAI25/8/202631/8/2026
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and…
AnalizadaAlta (8.2)0.32%—Oracle Email Center18/8/202631/8/2026
Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks…
AplazadaCrítica (9.8)0.50%—Wpfactory Customer Email Verification FOR WoocommerceAI13/8/202626/8/2026
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered…
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
AplazadaCrítica (9.8)0.48%—Kadence Woocommerce Email DesignerAI6/8/202612/8/2026
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
AplazadaBaja (1.9)0.21%—Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI3/8/202612/8/2026
A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with…
AplazadaMedia (6.4)0.35%—Sendpulse Email Marketing NewsletterAI1/8/202612/8/2026
The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
AplazadaMedia (6.5)0.40%—Check LOG EmailAI31/7/202626/8/2026
The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks.
AplazadaAlta (8.1)0.38%—Social Login Passkeys Magic Link Email OTPAI20/7/202621/7/2026
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email…
AnalizadaAlta (8.9)0.51%—Premailer CSS Parser17/7/202618/8/2026
css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection…
AplazadaAlta (7.5)0.24%—Seppmail Secure Email GatewayAISeppmail CloudAI17/7/202617/7/2026
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.
AplazadaAlta (7.1)0.25%—Siteground Email MarketingAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5.
Orbitaley — Vulnerabilidades