Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Gentoo Nullmailer | 23/5/2014 | 16/6/2026 | The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Phppower TOP Paidmailer | 26/3/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | JTR JAX Formmailer | 8/7/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the BASE_DIR[jax_formmailer] parameter. | |
| Modificada | Media (4.3) | 1.1% | — | CGI Rescue CGI WEB Mailer | 8/5/2009 | 16/6/2026 | CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP headers, and conduct cross-site scripting (XSS) or HTTP response splitting attacks, via CRLF sequences in an unspecified web form. | |
| Modificada | Media (4.3) | 1.2% | — | Perlmailer | 1/4/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PerlMailer before 3.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | VU Mass Mailer | 27/11/2007 | 16/6/2026 | SQL injection vulnerability in redir.asp in VU Mass Mailer allows remote attackers to execute arbitrary SQL commands via the password parameter to Default.asp (aka the Login Page). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 2.4% | — | Phpmailer | 14/6/2007 | 16/6/2026 | PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Triexa Sonicmailer PRO | 13/3/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action. | |
| Modificada | Alta (7.5) | 1.2% | — | SME Filemailer | 19/1/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in (a) index.php and (b) dl.php in SmE FileMailer 1.21 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ps, (2) us, (3) f, or (4) code parameter. NOTE: the us vector in index.php is already covered by CVE-2007-0346. | |
| Modificada | Alta (7.5) | 1.3% | — | Scriptme SME Filemailer | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in index.php (aka the login form) in Scriptme SMe FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the Password field (ps parameter). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | — | SME Filemailer | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in index.php in SmE FileMailer 1.21 allows remote attackers to execute arbitrary SQL commands via the us parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Chipmailer | 21/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in main.php in Chipmailer 1.09 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) betreff, (3) mail, and (4) text parameters. | |
| Modificada | Media (5) | 1.4% | — | Chipmailer | 21/6/2006 | 16/6/2026 | Chipmailer 1.09 allows remote attackers to obtain sensitive information via a direct request to php.php, which displays the output of the phpinfo function. | |
| Modificada | Alta (7.5) | 1.3% | — | Chipmailer | 21/6/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in main.php in Chipmailer 1.09 allow remote attackers to execute arbitrary SQL commands via multiple parameters, as demonstrated by (1) anfang, (2) name, (3) mail, (4) anrede, (5) vorname, (6) nachname, (7) gebtag, (8) gebmonat, and (9) gebjahr. | |
| Modificada | Media (5) | 4.5% | 💥 Exploit | Phpmailer | 28/5/2005 | 16/6/2026 | The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | PntresmailerAI | 10/1/2005 | 16/6/2026 | Directory traversal vulnerability in codebrowserpntm.php in pnTresMailer 6.0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the filetodownload parameter. | |
| Modificada | Media (5) | 1.7% | — | PntresmailerAI | 10/1/2005 | 16/6/2026 | codebrowserpntm.php in PnTresMailer 6.03 allows remote attackers to gain sensitive information via an invalid filetohighlight parameter, which reveals the full path in an error message. | |
| Modificada | Media (4.6) | 0.29% | — | Elmme-mailer ELM ME+ | 31/12/2003 | 16/6/2026 | Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group. | |
| Modificada | Alta (10) | 6.2% | — | Zmailer | 31/12/2002 | 16/6/2026 | Buffer overflow in ZMailer before 2.99.51_1 allows remote attackers to execute arbitrary code during HELO processing from an IPv6 address, possibly using an address that resolves to a long hostname. | |
| Modificada | Baja (2.1) | 0.34% | — | Nullmailer | 29/11/2002 | 16/6/2026 | nullmailer 1.00RC5 and earlier allows local users to cause a denial of service via an email to a local user that does not exist, which generates an error that causes nullmailer to stop sending mail to all users. | |
| Modificada | Alta (7.5) | 3.1% | — | Apple Claris Emailer | 31/12/2001 | 16/6/2026 | Buffer overflow in Claris Emailer 2.0v2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an email attachment with a long filename. | |
| Modificada | Baja (2.6) | 1.3% | — | Stalkerlab Mailers | 20/10/2000 | 16/6/2026 | CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable. |