Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
–

3278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.92%—Microengine Mailform23/5/202317/6/2026
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
ModificadaMedia (4.3)0.37%—Jenkins Email Extension16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Email Extension Plugin allows attackers to make another user stop watching an attacker-specified job.
ModificadaMedia (4.3)0.50%—Jenkins Email Extension16/5/202317/6/2026
Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system.
ModificadaMedia (5.4)0.37%—Webfwd Mail Subscribe List16/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Richard Leishman t/a Webforward Mail Subscribe List plugin <= 2.1.9 versions.
ModificadaMedia (6.1)0.38%—I13websolution Mass Email TO Users10/5/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Mass Email To users plugin <= 1.1.4 versions.
ModificadaMedia (6.1)0.38%—Cybonet Pineapp Mail Secure8/5/202317/6/2026
Cybonet PineApp Mail Secure A reflected cross-site scripting (XSS) vulnerability was identified in the product, using an unspecified endpoint.
ModificadaAlta (7.5)0.42%—Vk.company Mymail7/5/202317/6/2026
The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.
ModificadaCrítica (9.8)1.1%—Mailbutler Shimo4/5/202317/6/2026
An issue in the helper tool of Mailbutler GmbH Shimo VPN Client for macOS v5.0.4 allows attackers to bypass authentication via PID re-use.
ModificadaMedia (4.8)0.39%—Winwar WP Email Capture2/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Winwar Media WP Email Capture plugin <= 3.9.3 versions.
ModificadaMedia (4.8)0.53%—Smtp Mailing Queue Project Smtp Mailing Queue2/5/202317/6/2026
The SMTP Mailing Queue WordPress plugin before 2.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.1)0.57%—Webfwd Mail Subscribe List2/5/202316/6/2026
A vulnerability, which was classified as problematic, has been found in Mail Subscribe List Plugin up to 2.0.10 on WordPress. This issue affects some unknown processing of the file index.php. The manipulation of the argument sml_name/sml_email leads to cross site scripting. The attack may be initiated remotely.…
ModificadaMedia (6.1)0.56%—Yikesinc Easy Forms FOR Mailchimp24/4/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.8 does not sanitise and escape some parameters before outputting them back in the response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (5.4)0.53%—Yikesinc Easy Forms FOR Mailchimp17/4/202317/6/2026
The Easy Forms for Mailchimp WordPress plugin before 6.8.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.3)0.30%—GNU Mailman15/4/202317/6/2026
An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this,…
ModificadaAlta (7.8)0.51%—Chinamobileltd OA Mailbox PC10/4/202317/6/2026
An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.
ModificadaMedia (4.8)0.39%—Mailoptin6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MailOptin Popup Builder Team MailOptin plugin <= 1.2.54.0 versions.
ModificadaMedia (4.8)0.39%—Wpfrom Email Project Wpfrom Email6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPGear.Pro WPFrom Email plugin <= 1.8.8 versions.
ModificadaMedia (6.1)0.37%—Acymailing30/3/202317/6/2026
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
ModificadaAlta (7.5)0.63%—Acymailing30/3/202317/6/2026
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below…
ModificadaCrítica (9.8)1.8%—Acymailing30/3/202317/6/2026
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
ModificadaMedia (5.3)0.60%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock has vulnerability of insufficient access control. An unauthenticated remote user can exploit this vulnerability to access partial content of another user’s mail by changing user ID and mail ID within URL.
ModificadaAlta (7.2)0.93%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operation or disrupt service.
ModificadaAlta (7.2)0.93%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock mail query function has vulnerability of insufficient validation for user input. An authenticated remote attacker with administrator privilege can exploit this vulnerability to inject SQL commands to read, modify, and delete the database.
ModificadaMedia (6.1)0.49%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack.
ModificadaMedia (5.4)0.43%—Openfind Mail200027/3/202317/6/2026
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack.