Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
3278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.34% | — | Wpo365 Mail Integration FOR Office 365 / Outlook | 23/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPO365 | Mail Integration for Office 365 / Outlook plugin <= 1.9.0 versions. | |
| Modificada | Media (5.3) | 0.51% | — | Acymailing | 17/8/2023 | 17/6/2026 | Vulnerabilidad de exposición de información sensible en el componente AcyMailing Enterprise para Joomla. Permite a actores no autorizados obtener el número de suscriptores de una lista específica. | |
| Modificada | Media (4.3) | 0.40% | — | Acymailing | 17/8/2023 | 17/6/2026 | Vulnerabilidad de control de acceso inadecuado en el componente AcyMailing Enterprise para Joomla. Permite la eliminación no autorizada de archivos adjuntos de las campañas. | |
| Modificada | Media (4.3) | 0.40% | — | Acymailing | 17/8/2023 | 17/6/2026 | Vulnerabilidad de control de acceso inadecuado en el componente AcyMailing Enterprise para Joomla. Permite a usuarios no autorizados crear nuevas listas de correo. | |
| Modificada | Media (6.1) | 0.40% | — | Acymailing | 17/8/2023 | 17/6/2026 | La vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web en el componente AcyMailing Enterprise para Joomla permite Cross-Site Scripting (XSS). Este problema afecta al componente AcyMailing Enterprise para Joomla: 6.7.0-8.6.3. | |
| Modificada | Crítica (9.8) | 1.1% | — | Acyba Acymailing Starter | 17/8/2023 | 17/6/2026 | Vulnerabilidad de carga no restringida de archivos de tipo peligroso en el componente AcyMailing para Joomla. Permite la ejecución remota de código. | |
| Modificada | Media (4.8) | 0.47% | — | Lesterchan Wp-email | 14/8/2023 | 17/6/2026 | The WP-EMail WordPress plugin before 2.69.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (6.1) | 0.41% | — | I13websolution Email Subscription Popup | 14/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento I Thirteen Web Solution Email Subscription Popup versiones <= 1.2.16. | |
| Modificada | Alta (7.8) | 0.18% | — | Eset Endpoint AntivirusEset Endpoint SecurityEset Internet SecurityEset Mail Security+4 | 14/8/2023 | 17/6/2026 | The vulnerability potentially allows an attacker to misuse ESET’s file operations during the module update to delete or move files without having proper permissions. | |
| Modificada | Media (6.5) | 0.83% | — | Davesteele Gnome-gmail | 11/8/2023 | 17/6/2026 | Se ha descubierto un problema en el parámetro "attach" de la versión 2.5.4 de GNOME Gmail, que permite a atacantes remotos obtener información confidencial a través de un enlace "mailto" manipulado. | |
| Modificada | Media (6.1) | 0.36% | — | Yikesinc Easy Forms FOR Mailchimp | 10/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in YIKES, Inc. Easy Forms for Mailchimp plugin <= 6.8.8 versions. | |
| Modificada | Alta (8.8) | 0.34% | — | Lw-systems Benno Mailarchiv | 9/8/2023 | 17/6/2026 | Se ha descubierto una vulnerabilidad de Cross-Site Request Forgery (CSRF) en LWsystems Benno MailArchiv v2.10.1. | |
| Modificada | Media (6.1) | 0.44% | — | Lw-systems Benno Mailarchiv | 9/8/2023 | 17/6/2026 | Se ha descubierto un problema en LWsystems Benno MailArchiv v2.10.1. Los atacantes pueden causar Cross-Site Scripting (XSS) a través de contenido JavaScript a un buzón de correo. | |
| Modificada | Media (6.1) | 0.38% | — | Eggemplo Woocommerce Email Report | 8/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in eggemplo Woocommerce Email Report plugin <= 2.4 versions. | |
| Modificada | Media (6.1) | 0.44% | — | Atmail | 27/7/2023 | 17/6/2026 | Atmail v5.62 permite ataques de tipo Cross-Site Scripting (XSS) a través del campo "mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.html Search Terms". | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Icewarp ServerIcewarp Mail Server | 27/7/2023 | 9/7/2026 | Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter. | |
| Modificada | Alta (8.8) | 0.25% | — | WP Reroute Email Project WP Reroute Email | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions. | |
| Modificada | Media (6.1) | 0.46% | — | WP Reroute Email Project WP Reroute Email | 12/7/2023 | 17/6/2026 | The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.44% | — | Webdesignmunich Mail Queue | 12/7/2023 | 17/6/2026 | The Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.46% | — | Lanacodes Lana Email Logger | 12/7/2023 | 17/6/2026 | The Lana Email Logger plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, Lana Email Logger due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.60% | — | Instareza Mail Control | 12/7/2023 | 17/6/2026 | The Mail Control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 0.2.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.46% | — | Oacstudio Mailtree LOG Mail | 12/7/2023 | 17/6/2026 | The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will… | |
| Modificada | Media (6.1) | 0.46% | — | Dev4press GD Mail Queue | 12/7/2023 | 17/6/2026 | The GD Mail Queue plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.49% | — | Photoboxone Smtp Mail | 12/7/2023 | 17/6/2026 | The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.3.46 due to insufficient input sanitization and output escaping when the 'Save Data SendMail' feature is enabled. This makes it possible for unauthenticated attackers to inject… | |
| Modificada | Media (6.1) | 0.46% | — | Wpvibes WP Mail LOG | 12/7/2023 | 17/6/2026 | The WP Mail Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… |