Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Wp-buy Conditional Marketing Mailer | 14/5/2021 | 17/6/2026 | Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps… | |
| Modificada | Crítica (9.8) | 3.1% | — | Phpmailer Project PhpmailerWordpress | 28/4/2021 | 17/6/2026 | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an… | |
| Modificada | Crítica (9.8) | 3.3% | — | AcmailerAcmailer DB | 14/1/2021 | 17/6/2026 | Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors. | |
| Modificada | Crítica (9.8) | 7.9% | 💥 Exploit | AcmailerAcmailer DB | 14/1/2021 | 17/6/2026 | Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.3% | — | Nodemailer | 12/11/2020 | 17/6/2026 | This affects the package nodemailer before 6.4.16. Use of crafted recipient email addresses may result in arbitrary command flag injection in sendmail transport for sending mails. | |
| Modificada | Media (4.8) | 0.96% | — | Jenkins Mailer | 16/9/2020 | 17/6/2026 | Jenkins Mailer Plugin 1.32 and earlier does not perform hostname validation when connecting to the configured SMTP server. | |
| Modificada | Crítica (9.8) | 33% | 💥 Exploit | Superwebmailer | 14/7/2020 | 17/6/2026 | SuperWebMailer 7.21.0.01526 is susceptible to a remote code execution vulnerability in the Language parameter of mailingupgrade.php. An unauthenticated remote attacker can exploit this behavior to execute arbitrary PHP code via Code Injection. | |
| Modificada | Alta (7.5) | 3.8% | — | Phpmailer Project PhpmailerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 8/6/2020 | 17/6/2026 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message. | |
| Modificada | Alta (8.8) | 2.2% | — | Phpmailer Project PhpmailerDebian LinuxFedoraproject FedoraWordpress | 16/11/2018 | 17/6/2026 | PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. | |
| Modificada | Baja (3.7) | 1.6% | — | Jenkins Mailer | 27/7/2018 | 17/6/2026 | jenkins-mailer-plugin before version 1.20 is vulnerable to an information disclosure while using the feature to send emails to a dynamically created list of users based on the changelogs. This could in some cases result in emails being sent to people who have no user account in Jenkins, and in rare cases even people… | |
| Modificada | Alta (7.5) | 1.2% | — | Nodemailer.js Project Nodemailer.js | 7/6/2018 | 17/6/2026 | nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (7.5) | 1.1% | — | Nodemailer-js Project Nodemailer-js | 7/6/2018 | 17/6/2026 | nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Alta (8) | 6.5% | 💥 Exploit | Jenkins Mailer | 27/3/2018 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated users to send unauthorized mail as an arbitrary user via a /descriptorByName/hudson.tasks.Mailer/sendTestMail request. | |
| Modificada | Media (6.1) | 2.4% | 💥 PoC | Phpmailer Project Phpmailer | 20/7/2017 | 17/6/2026 | PHPMailer 5.2.23 has XSS in the "From Email Address" and "To Email Address" fields of code_generator.php. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | Dfsol Nuevomailer | 19/6/2017 | 17/6/2026 | SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter. | |
| Modificada | Media (5.5) | 2.2% | 💥 Exploit | Phpmailer Project Phpmailer | 16/1/2017 | 17/6/2026 | An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided,… | |
| Modificada | Crítica (9.8) | 42% | 💥 Exploit | Swiftmailer | 30/12/2016 | 17/6/2026 | The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header. | |
| Modificada | Crítica (9.8) | 98% | 💥 Exploit | Phpmailer Project PhpmailerWordpressJoomla! | 30/12/2016 | 17/6/2026 | The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Phpmailer Project PhpmailerWordpressJoomla! | 30/12/2016 | 17/6/2026 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property. | |
| Modificada | Crítica (9.1) | 2.4% | — | Seeds Acmailer | 16/1/2016 | 17/6/2026 | Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Media (5) | 2.0% | — | Debian LinuxPhpmailer Project Phpmailer | 16/12/2015 | 17/6/2026 | Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than… | |
| Modificada | Media (5.5) | 1.6% | — | Seeds Acmailer | 19/7/2015 | 17/6/2026 | Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string. | |
| Modificada | Media (4.3) | 1.9% | — | Superwebmailer | 19/3/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Homepage Decorator Perlmailer Project Homepage Decorator Perlmailer | 29/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Homepage Decorator PerlMailer 3.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 0.92% | — | Seeds Acmailer | 29/7/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization. |