Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3272 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.69%—KamailioAI20/9/202622/9/2026
A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2.0-dev1. The impacted element is the function shm_malloc of the file src/modules/cdp/receiver.c of the component CDP Diameter Receiver. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely.…
AplazadaMedia (5.3)0.30%—Mailchimp FOR WoocommerceAI19/9/202621/9/2026
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting user holds the required capability in the permission callback for several of its REST API routes, allowing unauthenticated users to reach administrator-oriented endpoints and trigger a persistent state change.
Pendiente de análisisMedia (6.1)0.33%—FairmailAI17/9/202623/9/2026
FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incompletely sanitizes untrusted message HTML. For non-allowlisted hosts,…
AplazadaCrítica (9.8)0.32%—Maildata Email Archiving SystemAI17/9/202622/9/2026
In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
AplazadaBaja (2.1)0.84%—Punchin-emailAICloudflare WorkersAI17/9/202630/9/2026
punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-To header intended to route responses through the relay. When a correspondent…
Pendiente de análisisAlta (8.3)0.40%—NodemailerAI16/9/202622/9/2026
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain…
Pendiente de análisisAlta (8.3)0.38%—NodemailerAI16/9/202622/9/2026
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the…
Pendiente de análisisAlta (8.7)0.82%—NodemailerAI16/9/202622/9/2026
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for…
Pendiente de análisisMedia (6)0.29%—NodemailerAI16/9/202622/9/2026
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key,…
Pendiente de análisisCrítica (9.8)0.53%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisAlta (7.5)0.47%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202616/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.53%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.62%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.40%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
AplazadaAlta (8.8)0.33%—Typo3AITypo3 Direct MailAI14/9/202622/9/2026
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4…
AplazadaMedia (4.3)0.33%—N-able Mail AssureAI13/9/202622/9/2026
N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender…
AplazadaMedia (6.9)0.76%—Simalexan Api-lambda-send-email-sesAI13/9/202614/9/2026
A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing…
Pendiente de análisisAlta (8.7)0.68%—NodemailerAI13/9/202624/9/2026
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several…
AplazadaAlta (7.5)0.93%—AcymailingAI11/9/202611/9/2026
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary…
AplazadaAlta (7.1)0.40%—Mailmunch Grow Your Email ListAI10/9/202610/9/2026
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Pendiente de análisisCrítica (9.9)0.86%—CpanelAICpanel EmailtrackAI9/9/202610/9/2026
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
AplazadaMedia (4.9)0.31%—Mail MintAI9/9/20269/9/2026
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AnalizadaMedia (4.8)0.08%—Samsung Visual Voicemail9/9/202623/9/2026
Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
AplazadaMedia (6.5)0.33%—Blog Studio Email Subscribers AND NewslettersAI7/9/20268/9/2026
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly…
AplazadaCrítica (9.8)0.66%—Mail MintAI5/9/20268/9/2026
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated…