Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | Myriadsolutionz Stars Smtp MailerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Reflected XSS.This issue affects Stars SMTP Mailer: from n/a through <= 1.7. | |
| Analizada | Alta (8.8) | 0.20% | — | Drupal Symfony Mailer Lite Project Drupal Symfony Mailer Lite | 9/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6. | |
| Analizada | Crítica (9.1) | 0.37% | — | Swift Mailer Project Swift Mailer | 9/1/2025 | 17/6/2026 | Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*. | |
| Aplazada | Media (4.3) | 0.36% | — | Davidcramer Caldera Smtp MailerAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in David Cramer Caldera SMTP Mailer caldera-smtp-mailer.This issue affects Caldera SMTP Mailer: from n/a through <= 1.0.1. | |
| En análisis | Alta (8.8) | 0.49% | — | Myriadsolutionz Stars Smtp Mailer | 4/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Upload a Web Shell to a Web Server.This issue affects Stars SMTP Mailer: from n/a through <= 2.2.1. | |
| Aplazada | Media (6.6) | 0.94% | — | Rubyonrails Action MailerAI | 16/10/2024 | 17/6/2026 | Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the block_format helper in Action Mailer. Carefully crafted text can cause the block_format helper to take an unexpected… | |
| Aplazada | Media (4.3) | 0.41% | — | Mailerlite - Woocommerce IntegrationAI | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8. | |
| Aplazada | Media (6.3) | 0.27% | — | PHP Server MonitorAIPhpmailerAI | 24/5/2024 | 17/6/2026 | PHP Server Monitor, version 3.2.0, is vulnerable to an XSS via the /phpservermon-3.2.0/vendor/phpmailer/phpmailer/test_script/index.php page in all visible parameters. An attacker could create a specially crafted URL, send it to a victim and retrieve their session details. | |
| Aplazada | Media (5.3) | 0.50% | — | Mailerlite Signup FormsAI | 2/5/2024 | 17/6/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized plugin setting changes due to a missing capability check on the toggleRolesAndPermissions and editAllowedRolesAndPermissions functions in all versions up to, and including, 1.7.6. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.42% | — | Mailerlite Signup FormsAI | 2/5/2024 | 17/6/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (8.8) | 0.21% | — | Mailerlite | 28/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8. | |
| Modificada | Media (6.1) | 0.92% | 💥 Exploit | Superwebmailer | 7/2/2024 | 17/6/2026 | SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the component api.php. | |
| Modificada | Media (5.5) | 0.22% | — | Supermailer | 13/12/2023 | 17/6/2026 | Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11.20.0.2204. An attacker could exploit this vulnerability by sending a malicious configuration file (file with SMB extension) to a user via a link or email attachment and persuade the user to open the file with the affected… | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows keepalive.php XSS via a GET parameter. | |
| Modificada | Alta (8.8) | 1.3% | — | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line. | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows superadmincreate.php XSS via crafted incorrect passwords. | |
| Modificada | Alta (8.8) | 0.66% | — | Superwebmailer | 21/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Export SQL Injection via the size parameter. | |
| Modificada | Media (6.1) | 0.48% | — | Superwebmailer | 20/10/2023 | 17/6/2026 | An issue was discovered in SuperWebMailer 9.00.0.01710. It allows spamtest_external.php XSS via a crafted filename. | |
| Modificada | Alta (8.8) | 0.38% | — | Mailerlite Signup Forms | 5/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key. | |
| Modificada | Media (6.1) | 0.85% | — | Mailerlite Signup Forms | 13/6/2022 | 17/6/2026 | The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (4.3) | 1.1% | — | Jenkins MailerOracle Communications Cloud Native Core Automated Test Suite | 12/1/2022 | 17/6/2026 | A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname. | |
| Modificada | Media (4.3) | 0.96% | — | Jenkins MailerOracle Communications Cloud Native Core Automated Test Suite | 12/1/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname. | |
| Modificada | Alta (8.8) | 1.4% | — | Nodemailer | 29/6/2021 | 17/6/2026 | The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object. | |
| Modificada | Alta (8.1) | 2.3% | — | Phpmailer Project PhpmailerFedoraproject Fedora | 17/6/2021 | 17/6/2026 | PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace… | |
| Modificada | Alta (8.1) | 2.8% | — | Phpmailer Project PhpmailerFedoraproject Fedora | 16/6/2021 | 17/6/2026 | PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. |