Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.41%—Myriadsolutionz Stars Smtp MailerAI16/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Reflected XSS.This issue affects Stars SMTP Mailer: from n/a through <= 1.7.
AnalizadaAlta (8.8)0.20%—Drupal Symfony Mailer Lite Project Drupal Symfony Mailer Lite9/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.
AnalizadaCrítica (9.1)0.37%—Swift Mailer Project Swift Mailer9/1/202517/6/2026
Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.
AplazadaMedia (4.3)0.36%—Davidcramer Caldera Smtp MailerAI16/12/202417/6/2026
Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera SMTP Mailer: from n/a through <= 1.0.1.
En análisisAlta (8.8)0.49%—Myriadsolutionz Stars Smtp Mailer4/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through <= 2.2.1.
AplazadaMedia (6.6)0.94%—Rubyonrails Action MailerAI16/10/202417/6/2026
Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully crafted text can cause the block_format helper to take an unexpected…
AplazadaMedia (4.3)0.41%—Mailerlite - Woocommerce IntegrationAI11/6/202417/6/2026
Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.
AplazadaMedia (6.3)0.27%—PHP Server MonitorAIPhpmailerAI24/5/202417/6/2026
PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details.
AplazadaMedia (5.3)0.50%—Mailerlite Signup FormsAI2/5/202417/6/2026
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated…
AplazadaMedia (6.4)0.42%—Mailerlite Signup FormsAI2/5/202417/6/2026
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with…
ModificadaAlta (8.8)0.21%—Mailerlite28/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.
ModificadaMedia (6.1)0.92%💥 ExploitSuperwebmailer7/2/202417/6/2026
SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php.
ModificadaMedia (5.5)0.22%—Supermailer13/12/202317/6/2026
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerability by sending a malicious configuration file (file with SMB extension) to a user via a link or email attachment and persuade the user to open the file with the affected…
ModificadaMedia (6.1)1.1%💥 ExploitSuperwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter.
ModificadaAlta (8.8)1.3%—Superwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
ModificadaMedia (6.1)1.1%💥 ExploitSuperwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords.
ModificadaAlta (8.8)0.66%—Superwebmailer21/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter.
ModificadaMedia (6.1)0.48%—Superwebmailer20/10/202317/6/2026
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename.
ModificadaAlta (8.8)0.38%—Mailerlite Signup Forms5/8/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
ModificadaMedia (6.1)0.85%—Mailerlite Signup Forms13/6/202217/6/2026
The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
ModificadaMedia (4.3)1.1%—Jenkins MailerOracle Communications Cloud Native Core Automated Test Suite12/1/202217/6/2026
A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
ModificadaMedia (4.3)0.96%—Jenkins MailerOracle Communications Cloud Native Core Automated Test Suite12/1/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.
ModificadaAlta (8.8)1.4%—Nodemailer29/6/202117/6/2026
The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.
ModificadaAlta (8.1)2.3%—Phpmailer Project PhpmailerFedoraproject Fedora17/6/202117/6/2026
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace…
ModificadaAlta (8.1)2.8%—Phpmailer Project PhpmailerFedoraproject Fedora16/6/202117/6/2026
PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname.
Orbitaley — Vulnerabilidades