Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

4600 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.77%—Stamparm MaltrailAI15/9/202615/9/2026
A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the…
AplazadaMedia (5.5)0.43%—Phpgurukul Daily Expense Tracker SystemAI15/9/202615/9/2026
A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public…
AplazadaBaja (2)0.35%—Phpgurukul Daily Expense Tracker SystemAI15/9/202615/9/2026
A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The exploit has been published and may be…
AplazadaMedia (5.5)0.43%—Phpgurukul Daily Expense Tracker SystemAI15/9/202615/9/2026
A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and…
Pendiente de análisisCrítica (9.8)0.53%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisAlta (7.5)0.47%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202616/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.53%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.62%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Pendiente de análisisCrítica (9.8)0.40%—Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI14/9/202615/9/2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
AplazadaAlta (8.8)0.33%—Typo3AITypo3 Direct MailAI14/9/202622/9/2026
An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead to Configuration Injection (TYPO3 10.4…
AplazadaMedia (4.3)0.33%—N-able Mail AssureAI13/9/202622/9/2026
N-able Mail Assure through April 2026 contains a design-level authorization flaw that allows an authenticated SMTP user to send outbound email using MAIL FROM addresses belonging to other tenants. When connecting to the SMTP TCP port and performing SMTP AUTH with valid credentials, the server accepts arbitrary sender…
AplazadaMedia (6.9)0.76%—Simalexan Api-lambda-send-email-sesAI13/9/202614/9/2026
A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument toEmails/ccEmails/replyToEmails/subject/message causes missing…
Pendiente de análisisAlta (8.7)0.68%—NodemailerAI13/9/202624/9/2026
Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several…
AplazadaCrítica (9.3)0.59%—TailwindcssAIGohugo HugoAI11/9/202624/9/2026
Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As a result, the restrictions intended by the…
AplazadaAlta (7.5)0.93%—AcymailingAI11/9/202611/9/2026
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary…
AplazadaAlta (7.1)0.40%—Mailmunch Grow Your Email ListAI10/9/202610/9/2026
Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Pendiente de análisisCrítica (9.9)0.86%💥 PoCCpanelAICpanel EmailtrackAI9/9/202610/9/2026
A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component
AplazadaMedia (4.9)0.31%—Mail MintAI9/9/20269/9/2026
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to SQL Injection via the 'status' parameter in all versions up to, and including, 1.31.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
AnalizadaMedia (4.8)0.08%—Samsung Visual Voicemail9/9/202623/9/2026
Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.
AplazadaMedia (6.5)0.33%—Blog Studio Email Subscribers AND NewslettersAI7/9/20268/9/2026
The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due to the software allowing users to execute an action that does not properly…
AplazadaMedia (5.5)0.53%—Code-projects Daily Expense ManagerAI6/9/20268/9/2026
A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been…
AplazadaCrítica (9.8)0.66%💥 PoCMail MintAI5/9/20268/9/2026
The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This makes it possible for unauthenticated…
Pendiente de análisisAlta (8.9)0.51%💥 PoCLaravelAISymfony MailerAISymfony MimeAI4/9/202610/9/2026
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in…
AplazadaMedia (6.5)0.27%—Mail MintAI3/9/20263/9/2026
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
AplazadaCrítica (9.8)0.56%💥 PoCMail MintAI3/9/20265/9/2026
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.