Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

122 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—Wp-buy Conditional Marketing Mailer14/5/202117/6/2026
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps…
ModificadaCrítica (9.8)3.1%—Phpmailer Project PhpmailerWordpress28/4/202117/6/2026
PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an…
ModificadaCrítica (9.8)3.3%—AcmailerAcmailer DB14/1/202117/6/2026
Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors.
ModificadaCrítica (9.8)7.9%💥 ExploitAcmailerAcmailer DB14/1/202117/6/2026
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors.
ModificadaCrítica (9.8)2.3%—Nodemailer12/11/202017/6/2026
This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails.
ModificadaMedia (4.8)0.96%—Jenkins Mailer16/9/202017/6/2026
Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server.
ModificadaCrítica (9.8)33%💥 ExploitSuperwebmailer14/7/202017/6/2026
SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection.
ModificadaAlta (7.5)3.8%—Phpmailer Project PhpmailerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux8/6/202017/6/2026
PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message.
ModificadaAlta (8.8)2.2%—Phpmailer Project PhpmailerDebian LinuxFedoraproject FedoraWordpress16/11/201817/6/2026
PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
ModificadaBaja (3.7)1.6%—Jenkins Mailer27/7/201817/6/2026
jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people…
ModificadaAlta (7.5)1.2%—Nodemailer.js Project Nodemailer.js7/6/201817/6/2026
nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (7.5)1.1%—Nodemailer-js Project Nodemailer-js7/6/201817/6/2026
nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
ModificadaAlta (8)6.5%💥 ExploitJenkins Mailer27/3/201817/6/2026
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request.
ModificadaMedia (6.1)2.4%💥 PoCPhpmailer Project Phpmailer20/7/201717/6/2026
PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php.
ModificadaCrítica (9.8)2.0%💥 ExploitDfsol Nuevomailer19/6/201717/6/2026
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.
ModificadaMedia (5.5)2.2%💥 ExploitPhpmailer Project Phpmailer16/1/201717/6/2026
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided,…
ModificadaCrítica (9.8)42%💥 ExploitSwiftmailer30/12/201617/6/2026
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.
ModificadaCrítica (9.8)98%💥 ExploitPhpmailer Project PhpmailerWordpressJoomla!30/12/201617/6/2026
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitPhpmailer Project PhpmailerWordpressJoomla!30/12/201617/6/2026
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
ModificadaCrítica (9.1)2.4%—Seeds Acmailer16/1/201617/6/2026
Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
ModificadaMedia (5)2.0%—Debian LinuxPhpmailer Project Phpmailer16/12/201517/6/2026
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than…
ModificadaMedia (5.5)1.6%—Seeds Acmailer19/7/201517/6/2026
Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string.
ModificadaMedia (4.3)1.9%—Superwebmailer19/3/201517/6/2026
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.
ModificadaMedia (4.3)1.1%—Homepage Decorator Perlmailer Project Homepage Decorator Perlmailer29/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)0.92%—Seeds Acmailer29/7/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization.
Orbitaley — Vulnerabilidades