Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
3272 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.5) | 0.28% | — | Apple MailAIApple CalendarAIApple ContactsAIHCL TravelerAI | 26/8/2026 | 28/8/2026 | The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them. The values cannot be changed later on, so the Apple profile generation page asks for those values and reflects them back in the… | |
| Aplazada | Alta (8.5) | 0.39% | — | Stalwart Mail ServerAI | 26/8/2026 | 24/9/2026 | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the… | |
| Pendiente de análisis | Media (5.7) | 0.19% | — | Drupal Email Login OTPAI | 25/8/2026 | 28/8/2026 | Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*. | |
| Aplazada | Crítica (9.5) | 0.97% | — | In2code PowermailAI | 25/8/2026 | 28/9/2026 | The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers… | |
| Aplazada | Alta (8.7) | 0.66% | — | Getgrav Grav-plugin-emailAI | 25/8/2026 | 31/8/2026 | The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled Email action parameters as unsandboxed Twig templates. An authenticated remote user with only api.access and api.pages.write permissions can place a Twig expression in header.form.process.email.body, publish the page, and… | |
| Pendiente de análisis | Media (6.4) | 0.11% | — | Zephyr RtosAINXP Mailbox DriverAI | 24/8/2026 | 26/8/2026 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live userspace memory, and then forwarded the original, still-mutable userspace struct mbox_msg * pointer to z_impl_mbox_send() and the underlying driver.… | |
| Aplazada | Media (6.4) | 0.33% | — | Ibericode Mailchimp FOR WordpressAI | 22/8/2026 | 24/8/2026 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Crítica (9.8) | 0.79% | — | Mailgun FOR WordpressAI | 22/8/2026 | 25/8/2026 | The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from $_POST['addresses'], passes them through… | |
| Aplazada | Media (6.5) | 0.22% | — | Axllent MailpitAI | 20/8/2026 | 18/9/2026 | Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw RequestURI for the /api/ prefix while Go's ServeMux routes using the percent-decoded URL path, and server/websockets/client.go configures websocket.Upgrader.CheckOrigin to… | |
| Aplazada | Media (5.3) | 0.51% | — | Axllent MailpitAI | 20/8/2026 | 18/9/2026 | Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.Reader.ReadBytes before applying the len(data)+len(line) size check to the completed SMTP DATA line against Server.MaxSize. An unauthenticated SMTP client can send a… | |
| Aplazada | Alta (7.5) | 0.36% | — | MailuAI | 20/8/2026 | 18/9/2026 | Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any unauthenticated attacker to remove any potential IP restriction or update the comment field from any existing user token provided the REST API is enabled. Upgrade to Mailu… | |
| Aplazada | Media (5.3) | 0.51% | — | Axllent MailpitAI | 20/8/2026 | 18/9/2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{id}/part/{partID}/thumb endpoint. The Thumbnail handler in… | |
| Aplazada | Media (5.3) | 0.51% | — | Axllent MailpitAI | 20/8/2026 | 18/9/2026 | Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses the verb or the RFC 5321 512-octet command-line limit is enforced. An unauthenticated remote SMTP… | |
| Aplazada | Alta (8.7) | 0.45% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | |
| Aplazada | Media (5.1) | 0.26% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | |
| Analizada | Alta (8.2) | 0.32% | — | Oracle Email Center | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle Email Center product of Oracle E-Business Suite (component: Message Component). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Successful attacks… | |
| Aplazada | Media (6.9) | 0.74% | — | Maalfer MailerupAI | 18/8/2026 | 1/9/2026 | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription… | |
| Analizada | Media (4.3) | 0.39% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver. | |
| Analizada | Alta (8.8) | 0.50% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.8) | 0.42% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540,… | |
| Analizada | Media (4.3) | 0.37% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. | |
| Analizada | Crítica (9.8) | 0.58% | — | Roundcube Webmail | 17/8/2026 | 10/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | |
| Analizada | Alta (7.1) | 2.3% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. | |
| Analizada | Media (5.8) | 0.47% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.4) | 0.30% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. |