Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.16% | — | Lettermint | 21/2/2026 | 17/6/2026 | Lettermint Node.js SDK is the official Node.js SDK for Lettermint. In versions 1.5.0 and below, email properties (such as to, subject, html, text, and attachments) are not reset between sends when a single client instance is reused across multiple .send() calls. This can cause properties from a previous send to leak… | |
| Aplazada | Alta (7.5) | 0.30% | — | Mail MintAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in WPFunnels Mail Mint mail-mint allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Mail Mint: from n/a through <= 1.19.4. | |
| Aplazada | Media (4.9) | 0.37% | — | Mail MintAI | 14/2/2026 | 17/6/2026 | The Mail Mint plugin for WordPress is vulnerable to blind SQL Injection via the 'forms', 'automation', 'email/templates', and 'contacts/import/tutorlms/map' API endpoints in all versions up to, and including, 1.19.2 . This is due to insufficient escaping on the user supplied 'order-by', 'order-type', and… | |
| Aplazada | Media (5.4) | 0.19% | — | Mail MintAI | 3/2/2026 | 17/6/2026 | The Mail Mint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.19.2. This is due to missing nonce validation on the create_or_update_note function. This makes it possible for unauthenticated attackers to create or update contact notes via a forged request granted… | |
| Analizada | Alta (7.2) | 0.95% | — | Mintplexlabs Anythingllm | 27/1/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration allows a malicious admin (or an attacker who can convince an admin to configure a malicious… | |
| Analizada | Alta (8.7) | 1.7% | — | Mintplexlabs Anythingllm | 27/1/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. If AnythingLLM prior to version 1.10.0 is configured to use Qdrant as the vector database with an API key, this QdrantApiKey could be exposed in plain text to unauthenticated users via the… | |
| Analizada | Media (5.3) | 0.76% | — | Mintplexlabs Anythingllm | 3/1/2026 | 17/6/2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username exists, so enabling username enumeration.… | |
| Analizada | Media (6.5) | 0.40% | — | Mintlify | 19/12/2025 | 17/6/2026 | The Deployment Infrastructure in Mintlify Platform before 2025-11-15 allows remote attackers to bypass security patches and execute downgrade attacks via predictable deployment identifiers on the Vercel preview domain. An attacker can identify the URL structure of a previous deployment that contains unpatched… | |
| Analizada | Media (5.4) | 0.52% | — | Mintlify | 19/12/2025 | 17/6/2026 | A Directory Traversal vulnerability in the Static Asset Proxy Endpoint in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing path traversal sequences. | |
| Analizada | Media (4.3) | 0.41% | — | Mintlify | 19/12/2025 | 17/6/2026 | The GitHub Integration API in Mintlify Platform before 2025-11-15 allows remote attackers to obtain sensitive repository metadata via the repository owner and name fields. It fails to validate that the repository owner and name fields provided during configuration belong to the specific GitHub App Installation ID… | |
| Analizada | Crítica (9.8) | 1.1% | — | Mintlify | 19/12/2025 | 17/6/2026 | A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file. | |
| Analizada | Media (5.4) | 0.36% | — | Mintlify | 19/12/2025 | 17/6/2026 | The Static Asset API in Mintlify Platform before 2025-11-15 allows remote attackers to inject arbitrary web script or HTML via the subdomain parameter because any tenant's assets can be served on any other tenant's documentation site. | |
| Modificada | Media (5.3) | 0.55% | — | Mintplexlabs Anythingllm | 18/12/2025 | 17/6/2026 | An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. Exposed data includes:… | |
| Aplazada | Media (5.3) | 0.23% | — | Xwiki AdmintoolsAI | 18/11/2025 | 17/6/2026 | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is visible to non admin users, the page is still… | |
| Aplazada | Media (5.3) | 0.29% | — | MinttyAI | 12/11/2025 | 17/6/2026 | Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access a file in a specific path. It is triggered by simply printing them out on bash. An attacker can specify an arbitrary network path, negotiate an ntlm hash out of the… | |
| Aplazada | Alta (7.2) | 0.53% | — | Mail MintAI | 8/11/2025 | 30/9/2026 | The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the process_contact_attribute_import function in all versions up to, and including, 1.18.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload… | |
| Aplazada | Alta (7.6) | 0.36% | — | Mail MintAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint mail-mint allows SQL Injection.This issue affects Mail Mint: from n/a through <= 1.18.6. | |
| Aplazada | Alta (7.6) | 0.36% | — | Mail MintAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint mail-mint allows SQL Injection.This issue affects Mail Mint: from n/a through <= 1.18.5. | |
| Analizada | Media (6.5) | 0.26% | — | Yaronkoren Mintydocs | 2/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2. | |
| Analizada | Baja (3.7) | 0.27% | — | Yaronkoren Mintydocs | 2/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MintyDocs Extension allows Stored XSS.This issue affects Mediawiki - MintyDocs Extension: from 1.43.X before 1.43.2. | |
| Aplazada | Alta (7.5) | 0.45% | — | Mail MintAI | 23/5/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WPFunnels Mail Mint mail-mint allows Retrieve Embedded Sensitive Data.This issue affects Mail Mint: from n/a through <= 1.17.7. | |
| Analizada | Media (5.3) | 0.33% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in xujiangfei admintwo 1.0. This affects an unknown part of the file /user/updateSet. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.40% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /user/updateSet. The manipulation of the argument email leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.54% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /user/home. The manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.55% | — | Xujiangfei Admintwo | 4/4/2025 | 17/6/2026 | A vulnerability was found in xujiangfei admintwo 1.0. It has been classified as critical. Affected is an unknown function of the file /resource/add. The manipulation of the argument description leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the… |