Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

3278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.65%—Awesomemotive WP Mail Logging12/7/202317/6/2026
The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (6.1)0.46%—Jamesward WP Mail Catcher12/7/202317/6/2026
The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (6.5)0.22%—Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions.
ModificadaAlta (7.5)1.3%—Synck Mailform PRO CGI29/6/202317/6/2026
Mailform Pro CGI v4.3.1.2 y anteriores permiten a un atacante remoto no autenticado causar una condición de Denegación de Servicios (DoS).
ModificadaMedia (6.1)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaMedia (6.1)0.51%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This…
ModificadaMedia (5.4)0.47%—Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance28/6/202317/6/2026
Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to…
ModificadaCrítica (9.8)0.51%—Forcepoint Email SecurityForcepoint WEB Security15/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.
ModificadaMedia (6.1)0.38%—Alinto Sogo WEB Mail14/6/202317/6/2026
Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code.
ModificadaMedia (5.4)0.51%—Codepeople Contact Form Email12/6/202317/6/2026
The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability.
ModificadaMedia (4.8)0.44%—Yikesinc Easy Forms FOR Mailchimp12/6/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaAlta (8.8)0.98%—Mailcow\7/6/202317/6/2026
mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using specially crafted passwords during the…
ModificadaAlta (8.8)1.2%—Wpexperts Email Templates7/6/202317/6/2026
The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators.
ModificadaMedia (6.1)0.74%—Codemiq WP Html Mail7/6/202317/6/2026
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an…
ModificadaMedia (6.1)0.58%—Codemiq WP Html Mail7/6/202317/6/2026
The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an…
ModificadaMedia (6.1)0.49%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe5/6/202317/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against…
ModificadaMedia (6.1)0.46%—Convertkit - Email Marketing, Email Newsletter AND Landing Pages5/6/202317/6/2026
The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaCrítica (9.8)1.2%—Wisetr User Email Verification FOR Woocommerce3/6/202317/6/2026
The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to…
ModificadaMedia (6.1)0.43%—Openfind Mail20002/6/202317/6/2026
Openfind Mail2000 tiene insuficientes caracteres especiales de filtrado de contenido de correo electrónico de su función de filtrado de contenido. Un atacante remoto puede explotar esta vulnerabilidad utilizando correos electrónicos de phising que contienen páginas web maliciosas inyectadas con JavaScript. Cuando los…
ModificadaMedia (6.1)1.1%💥 ExploitYikesinc Easy Forms FOR Mailchimp30/5/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
ModificadaMedia (4.8)0.37%—Pluginops Mailchimp Subscribe Form28/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions.
ModificadaMedia (5.3)0.53%—Nextcloud Mail27/5/202317/6/2026
Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.
AnalizadaCrítica (9.8)88%⚠ Explotación activa💥 ExploitBarracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+124/5/202317/6/2026
A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete…
ModificadaAlta (8.8)0.26%—Winwar WP Email Capture23/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.
ModificadaCrítica (9.8)1.3%—Microengine Mailform23/5/202317/6/2026
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
Orbitaley — Vulnerabilidades