Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
896 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.16% | — | Cisco Secure EmailAI | 2/9/2026 | 2/9/2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An… | |
| Aplazada | Alta (7.1) | 0.25% | — | Email EssentialsAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Email Subscribers AND NewslettersAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions. | |
| Pendiente de análisis | Crítica (9.3) | 2.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without… | |
| Pendiente de análisis | Media (6.9) | 1.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for… | |
| Pendiente de análisis | Alta (8.3) | 0.19% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls. | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny… | |
| Aplazada | Media (5.1) | 0.44% | — | Watchguard Dimension Email ServerAI | 28/8/2026 | 28/8/2026 | A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems. | |
| Pendiente de análisis | Media (5.7) | 0.19% | — | Drupal Email Login OTPAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | |
| Aplazada | Alta (8.7) | 0.66% | — | Getgrav Grav-plugin-emailAI | 25/8/2026 | 31/8/2026 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and… | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Email Center | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 13/8/2026 | 26/8/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Aplazada | Baja (1.9) | 0.21% | — | Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI | 3/8/2026 | 12/8/2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with… | |
| Aplazada | Media (6.4) | 0.35% | — | Sendpulse Email Marketing NewsletterAI | 1/8/2026 | 12/8/2026 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (6.5) | 0.40% | — | Check LOG EmailAI | 31/7/2026 | 26/8/2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 0.38% | — | Social Login Passkeys Magic Link Email OTPAI | 20/7/2026 | 21/7/2026 | The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email… | |
| Analizada | Alta (8.9) | 0.51% | — | Premailer CSS Parser | 17/7/2026 | 18/8/2026 | css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection… | |
| Aplazada | Alta (7.5) | 0.24% | — | Seppmail Secure Email GatewayAISeppmail CloudAI | 17/7/2026 | 17/7/2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header. | |
| Aplazada | Alta (7.1) | 0.25% | — | Siteground Email MarketingAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SiteGround SiteGround Email Marketing siteground-email-marketing allows Stored XSS.This issue affects SiteGround Email Marketing: from n/a through <= 1.7.5. |