Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
3278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.65% | — | Awesomemotive WP Mail Logging | 12/7/2023 | 17/6/2026 | The WP Mail Logging plugin for WordPress is vulnerable to Stored Cross-Site Scripting via email contents in versions up to, and including, 1.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.1) | 0.46% | — | Jamesward WP Mail Catcher | 12/7/2023 | 17/6/2026 | The WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 2.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute… | |
| Modificada | Media (6.5) | 0.22% | — | Disable Wordpress Update Notifications AND Auto-update Email Notifications Project Disable Wordpress Update Notifications AND Auto-update Email Notifications | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Prem Tiwari Disable WordPress Update Notifications and auto-update Email Notifications plugin <= 2.3.3 versions. | |
| Modificada | Alta (7.5) | 1.3% | — | Synck Mailform PRO CGI | 29/6/2023 | 17/6/2026 | Mailform Pro CGI v4.3.1.2 y anteriores permiten a un atacante remoto no autenticado causar una condición de Denegación de Servicios (DoS). | |
| Modificada | Media (6.1) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Media (6.1) | 0.51% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, formerly known as Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This… | |
| Modificada | Media (5.4) | 0.47% | — | Cisco Secure Email AND WEB ManagerCisco Secure Email GatewayCisco WEB Security Appliance | 28/6/2023 | 17/6/2026 | Multiple vulnerabilities in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager; Cisco Secure Email Gateway, formerly Cisco Email Security Appliance (ESA); and Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow a remote attacker to… | |
| Modificada | Crítica (9.8) | 0.51% | — | Forcepoint Email SecurityForcepoint WEB Security | 15/6/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection. | |
| Modificada | Media (6.1) | 0.38% | — | Alinto Sogo WEB Mail | 14/6/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in SOGo Web Mail before 4.3.1 allows attackers to obtain user sensitive information when a user reads an email containing malicious code. | |
| Modificada | Media (5.4) | 0.51% | — | Codepeople Contact Form Email | 12/6/2023 | 17/6/2026 | The Contact Form Email WordPress plugin before 1.3.38 does not escape submitted values before displaying them in the HTML, leading to a Stored XSS vulnerability. | |
| Modificada | Media (4.8) | 0.44% | — | Yikesinc Easy Forms FOR Mailchimp | 12/6/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape some of its from parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Alta (8.8) | 0.98% | — | Mailcow\ | 7/6/2023 | 17/6/2026 | mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate internal Dovecot variables by using specially crafted passwords during the… | |
| Modificada | Alta (8.8) | 1.2% | — | Wpexperts Email Templates | 7/6/2023 | 17/6/2026 | The Email Templates plugin for WordPress is vulnerable to HTML Injection in versions up to, and including, 1.3. This makes it possible for attackers to present phishing forms or conduct cross-site request forgery attacks against site administrators. | |
| Modificada | Media (6.1) | 0.74% | — | Codemiq WP Html Mail | 7/6/2023 | 17/6/2026 | The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.9.0.3 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an… | |
| Modificada | Media (6.1) | 0.58% | — | Codemiq WP Html Mail | 7/6/2023 | 17/6/2026 | The WP HTML Mail plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 2.2.10 due to insufficient input sanitization. This makes it possible for unauthenticated attackers to inject arbitrary HTML in pages that execute if they can successfully trick a administrator into performing an… | |
| Modificada | Media (6.1) | 0.49% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 5/6/2023 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.61 does not sanitise and escape a parameter before outputting it back in the admin dashboard when the WPML plugin is also active and configured, leading to a Reflected Cross-Site Scripting which could be used against… | |
| Modificada | Media (6.1) | 0.46% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 5/6/2023 | 17/6/2026 | The ConvertKit WordPress plugin before 2.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 1.2% | — | Wisetr User Email Verification FOR Woocommerce | 3/6/2023 | 17/6/2026 | The User Email Verification for WooCommerce plugin for WordPress is vulnerable to authentication bypass via authenticate_user_by_email in versions up to, and including, 3.5.0. This is due to a random token generation weakness in the resend_verification_email function. This allows unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.43% | — | Openfind Mail2000 | 2/6/2023 | 17/6/2026 | Openfind Mail2000 tiene insuficientes caracteres especiales de filtrado de contenido de correo electrónico de su función de filtrado de contenido. Un atacante remoto puede explotar esta vulnerabilidad utilizando correos electrónicos de phising que contienen páginas web maliciosas inyectadas con JavaScript. Cuando los… | |
| Modificada | Media (6.1) | 1.1% | 💥 Exploit | Yikesinc Easy Forms FOR Mailchimp | 30/5/2023 | 17/6/2026 | The Easy Forms for Mailchimp WordPress plugin before 6.8.9 does not sanitise and escape a parameter before outputting it back in the page when the debug option is enabled, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (4.8) | 0.37% | — | Pluginops Mailchimp Subscribe Form | 28/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PluginOps MailChimp Subscribe Form plugin <= 4.0.9.1 versions. | |
| Modificada | Media (5.3) | 0.53% | — | Nextcloud Mail | 27/5/2023 | 17/6/2026 | Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3. | |
| Analizada | Crítica (9.8) | 88% | ⚠ Explotación activa💥 Exploit | Barracuda Email Security Gateway 300 FirmwareBarracuda Email Security Gateway 400 FirmwareBarracuda Email Security Gateway 600 FirmwareBarracuda Email Security Gateway 800 Firmware+1 | 24/5/2023 | 17/6/2026 | A remote command injection vulnerability exists in the Barracuda Email Security Gateway (appliance form factor only) product effecting versions 5.1.3.001-9.2.0.006. The vulnerability arises out of a failure to comprehensively sanitize the processing of .tar file (tape archives). The vulnerability stems from incomplete… | |
| Modificada | Alta (8.8) | 0.26% | — | Winwar WP Email Capture | 23/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Microengine Mailform | 23/5/2023 | 17/6/2026 | MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it. |