Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
3278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.39% | — | WP Better Emails Project WP Better Emails | 20/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | Kamailio | 15/3/2023 | 17/6/2026 | The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact. | |
| Modificada | Media (5.3) | 1.8% | 💥 PoC | Fortinet Fortimail | 9/3/2023 | 17/6/2026 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form. | |
| Modificada | Crítica (9.8) | 0.63% | — | Email Registration Project Email Registration | 6/3/2023 | 16/6/2026 | A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to sql injection. The attack can be initiated remotely. Upgrading to… | |
| Modificada | Alta (8.8) | 2.2% | — | Mailcow\ | 4/3/2023 | 17/6/2026 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse this vulnerability to obtain shell access… | |
| Modificada | Media (6.7) | 0.45% | 💥 PoC | Cisco Email Security Appliance | 1/3/2023 | 17/6/2026 | Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A… | |
| Modificada | Alta (7.2) | 1.3% | 💥 PoC | Cisco Email Security ApplianceCisco Secure Email AND WEB Manager | 1/3/2023 | 17/6/2026 | A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user… | |
| Modificada | Alta (8.8) | 0.36% | — | Submitbymailplugin Project Submitbymailplugin | 20/2/2023 | 17/6/2026 | A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the file edit_list.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 1.0b2.9a is able to address this issue.… | |
| Modificada | Crítica (9.9) | 1.1% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields. | |
| Modificada | Media (5.3) | 0.72% | — | Sonicwall Email Security | 14/2/2023 | 17/6/2026 | SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses. | |
| Modificada | Media (5.3) | 0.46% | — | Nextcloud Mail | 13/2/2023 | 17/6/2026 | Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail… | |
| Modificada | Media (6.1) | 0.63% | — | Resend Welcome Email Project Resend Welcome Email | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading… | |
| Modificada | Media (4.3) | 0.92% | — | Nextcloud Mail | 6/2/2023 | 17/6/2026 | Nextcloud mail es una aplicación de correo electrónico para la plataforma de servidor doméstico nextcloud. En las versiones afectadas, los campos de host SMTP, IMAP y Sieve permitían escanear servicios internos y servidores accesibles desde la red local del servidor Nextcloud. Se recomienda actualizar la aplicación… | |
| Modificada | Media (6.5) | 0.47% | — | Nextcloud Mail | 6/2/2023 | 17/6/2026 | Nextcloud mail is an email app for the nextcloud home server platform. In versions prior to 2.2.2 user's passwords were stored in cleartext in the database during the duration of OAuth2 setup procedure. Any attacker or malicious user with access to the database would have access to these user passwords until the OAuth… | |
| Modificada | Media (5.4) | 0.65% | — | Cloak Front END Email Project Cloak Front END Email | 6/2/2023 | 17/6/2026 | The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Alta (8.8) | 0.26% | — | Wpvibes WP Mail LOG | 2/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in WPVibes WP Mail Log plugin <= 1.0.1 versions. | |
| Modificada | Media (6.1) | 0.51% | — | Mubag Easymail | 30/1/2023 | 17/6/2026 | Vulnerabilidad de cross-site scripting en EasyMail 2.00.130 y versiones anteriores permite que un atacante remoto no autenticado inyecte un script arbitrario. | |
| Modificada | Media (5.4) | 0.53% | — | Convertkit - Email Marketing, Email Newsletter AND Landing Pages | 16/1/2023 | 17/6/2026 | El complemento ConvertKit de WordPress anterior a 2.0.5 no valida ni escapa algunos de sus atributos de código corto antes de devolverlos a la página, lo que podría permitir a los usuarios con un rol tan bajo como el de colaborador realizar ataques de cross-site scripting almacenado, que podrían ser utilizado contra… | |
| Modificada | Alta (8.8) | 0.88% | — | Mailenable | 13/1/2023 | 17/6/2026 | Los usuarios de correo autenticados, en circunstancias específicas, podían agregar archivos con contenido no depurado en carpetas públicas a las que el usuario de IIS tenía permiso para acceder. Esa acción podría llevar a un atacante a almacenar código arbitrario en esos archivos y ejecutar comandos RCE. | |
| Modificada | Crítica (9.8) | 0.95% | — | Axigen Mail Server | 13/1/2023 | 17/6/2026 | Un problema de verificación en dos pasos en Axigen 10.3.3.52 permite a un atacante acceder a un buzón omitiendo la verificación en dos pasos cuando intenta agregar una cuenta a cualquier servicio de correo web de terceros (o agregar una cuenta a Outlook o Gmail, etc. ) con IMAP o POP3 sin ningún código de verificación. | |
| Modificada | Crítica (9.8) | 0.70% | — | Gmail-servlet Project Gmail-servlet | 11/1/2023 | 17/6/2026 | Se ha encontrado una vulnerabilidad en gmail-servlet y ha sido clasificada como crítica. Este problema afecta la función de búsqueda del archivo src/Model.java. La manipulación conduce a la inyección SQL. El identificador del parche es 5d72753c2e95bb373aa86824939397dc25f679ea. Se recomienda aplicar un parche para… | |
| Modificada | Alta (8.8) | 0.91% | — | Smackcoders Visual Email Designer FOR Woocommerce | 2/1/2023 | 17/6/2026 | El complemento Visual Email Designer for WooCommerce de WordPress anterior a 1.7.2 no sanitiza ni escapa adecuadamente un parámetro antes de usarlo en una declaración SQL, lo que genera una inyección de SQL explotable por usuarios con un rol tan bajo como el de autor. | |
| Modificada | Media (5.4) | 0.54% | — | Sangoma Voicemail | 27/12/2022 | 17/6/2026 | Se encontró una vulnerabilidad en FreeBPX voicemail. Ha sido calificada como problemática. Una función desconocida del archivo views/ssettings.php del componente Settings Handler es afectada por esta vulnerabilidad. La manipulación del argumento key conduce a Cross-Site Scripting. El ataque puede lanzarse de forma… |