Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 1.6% | — | EnigmailDebian Linux | 27/12/2017 | 17/6/2026 | An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001. | |
| Modificada | Media (6.5) | 1.4% | — | EnigmailDebian Linux | 27/12/2017 | 17/6/2026 | An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to automatically decrypt that block and then send it back to the attacker as quoted text, aka the… | |
| Modificada | Media (5.9) | 1.1% | — | EnigmailDebian Linux | 27/12/2017 | 17/6/2026 | An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack,… | |
| Modificada | Media (4.3) | 1.9% | — | Enigmail | 8/9/2014 | 17/6/2026 | Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (5) | 7.7% | — | Simple Gmail Login 1.1.2Simple Gmail Login 1.1.3 | 11/12/2012 | 16/6/2026 | simple-gmail-login.php in the Simple Gmail Login plugin before 1.1.4 for WordPress allows remote attackers to obtain sensitive information via a request that lacks a timezone, leading to disclosure of the installation path in a stack trace. | |
| Modificada | Media (4.3) | 1.7% | — | B1gmail | 19/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in hilfe.php in b1gMail 6.3.1 allows remote attackers to inject arbitrary web script or HTML via the chapter parameter. | |
| Modificada | Media (5) | 4.7% | — | Enigmail | 6/3/2007 | 16/6/2026 | Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection. | |
| Modificada | Alta (7.8) | 1.7% | — | Enigmail | 23/2/2007 | 16/6/2026 | The enigmail extension before 0.94.2 does not properly handle large, encrypted file e-mail attachments, which allows remote attackers to cause a denial of service (crash), as demonstrated with Mozilla Thunderbird. | |
| Modificada | Alta (7.5) | 1.3% | — | Viksoe Gmail Drive | 15/11/2006 | 16/6/2026 | viksoe GMail Drive shell extension allows remote attackers to perform virtual filesystem actions via e-mail messages with certain subject lines, as demonstrated by (1) a GMAILFS: [13;a;1] message with a new filename and a file attachment, which injects a new file into the filesystem; (2) a GMAILFS: [13;a;1] message… | |
| Modificada | Media (4.3) | 1.9% | — | GfhostGmailsite | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter. | |
| Modificada | Media (5) | 1.8% | — | Enigmail | 18/10/2005 | 16/6/2026 | The key selection dialogue in Enigmail before 0.92.1 can incorrectly select a key with a user ID that does not have additional information, which allows parties with that key to decrypt the message. | |
| Modificada | Alta (7.5) | 1.2% | — | Livingmailing | 2/6/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in livingmailing 1.3 allows remote attackers to execute arbitrary SQL commands via the password. NOTE: there is little public information about this product and its vendor, and the original researcher announcement is no longer available. |