Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

3272 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.9)0.51%💥 PoCLaravelAISymfony MailerAISymfony MimeAI4/9/202610/9/2026
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in…
AplazadaMedia (6.5)0.27%—Mail MintAI3/9/20263/9/2026
Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
AplazadaCrítica (9.8)0.56%💥 PoCMail MintAI3/9/20265/9/2026
Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.
AplazadaAlta (8.6)0.64%—Seppmail Secure Email GatewayAI3/9/20264/9/2026
SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
AplazadaAlta (7.7)0.47%—Seppmail Secure Email GatewayAI3/9/20263/9/2026
SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
AplazadaAlta (8.6)1.2%—Seppmail Secure Email GatewayAI3/9/20263/9/2026
SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
Pendiente de análisisMedia (5.9)0.16%—Cisco Secure EmailAI2/9/20262/9/2026
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An…
Pendiente de análisisMedia (5.9)0.16%—Cisco Secure EmailAI2/9/20262/9/2026
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An…
AplazadaMedia (5.4)0.14%—Simple Membership Mailchimp IntegrationAI2/9/20263/9/2026
The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration data (name, email, membership level) is…
AplazadaMedia (6.9)0.40%—Axllent MailpitAI2/9/202610/9/2026
Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in message content to reach the link check…
AnalizadaAlta (7.5)0.58%—Kamailio1/9/202615/9/2026
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec_agree()
AnalizadaAlta (7.5)0.58%—Kamailio1/9/20264/9/2026
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the IMS P-CSCF registration handling components
AplazadaBaja (3.5)0.29%—PhpmailerAIWallosapp WallosAI31/8/20268/9/2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled…
AplazadaAlta (7.1)0.25%—Email EssentialsAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
AplazadaAlta (7.1)0.25%—Email Subscribers AND NewslettersAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
Pendiente de análisisCrítica (9.3)2.0%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without…
Pendiente de análisisMedia (6.9)1.0%—NodemailerAI31/8/202610/9/2026
Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for…
Pendiente de análisisAlta (8.3)0.19%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised…
Pendiente de análisisMedia (5.3)0.26%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail…
Pendiente de análisisMedia (5.3)0.26%—NodemailerAI31/8/202610/9/2026
Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls.
Pendiente de análisisAlta (7.1)0.35%—NodemailerAI31/8/202610/9/2026
nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or…
Pendiente de análisisMedia (6.9)0.30%—NodemailerAI31/8/202610/9/2026
nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny…
AplazadaBaja (2.1)0.41%—KamailioAI31/8/202631/8/2026
A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from remote. The exploit has been publicly…
AplazadaCrítica (9.3)2.0%—Green-computing NumailAI28/8/202628/8/2026
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
AplazadaMedia (5.1)0.44%—Watchguard Dimension Email ServerAI28/8/202628/8/2026
A server-side request forgery (SSRF) vulnerability WatchGuard Dimension Email Server Test configuration allows an authenticated privileged attacker to enumerate exposed network services on adjacent network systems.