Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
177 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.5% | — | Wp-ecommerce Easy WP Smtp | 6/12/2022 | 17/6/2026 | Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | |
| Modificada | Media (6.5) | 0.84% | — | Wp-ecommerce Easy WP Smtp | 6/12/2022 | 17/6/2026 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress. | |
| Modificada | Alta (8.1) | 0.90% | — | Wp-ecommerce Easy WP Smtp | 6/12/2022 | 17/6/2026 | Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress. | |
| Modificada | Alta (7.2) | 1.2% | — | Wp-ecommerce Easy WP Smtp | 31/10/2022 | 17/6/2026 | The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. | |
| Modificada | Alta (7.2) | 1.3% | — | Wpexperts Post Smtp | 26/9/2022 | 17/6/2026 | The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example. | |
| Modificada | Media (4.8) | 0.68% | — | Wpexperts Post Smtp | 16/9/2022 | 17/6/2026 | The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 0.61% | — | Yaycommerce Yaysmtp | 8/8/2022 | 17/6/2026 | The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.4) | 0.61% | — | Yaycommerce Yaysmtp | 8/8/2022 | 17/6/2026 | The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well. | |
| Modificada | Media (6.5) | 0.92% | — | Yaycommerce Yaysmtp | 1/8/2022 | 17/6/2026 | The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them | |
| Modificada | Media (4.3) | 0.72% | — | Yaycommerce Yaysmtp | 1/8/2022 | 17/6/2026 | The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin | |
| Modificada | Media (6.5) | 0.53% | — | Webriti Smtp Mail | 13/6/2022 | 17/6/2026 | The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack | |
| Modificada | Media (6.1) | 0.80% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 14/2/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Media (6.1) | 0.81% | — | Brevo Newsletter, Smtp, Email Marketing AND Subscribe | 24/1/2022 | 17/6/2026 | The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue | |
| Modificada | Media (5.4) | 0.62% | — | Wpmanageninja Fluentsmtp | 30/8/2021 | 17/6/2026 | The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles… | |
| Modificada | Media (6.5) | 0.56% | — | Netexplorer MY Smtp Contact | 10/8/2021 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site. | |
| Modificada | Alta (7.5) | 3.7% | — | OpensmtpdFedoraproject Fedora | 24/12/2020 | 17/6/2026 | smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and… | |
| Modificada | Alta (7.5) | 2.9% | — | OpensmtpdFedoraproject Fedora | 24/12/2020 | 17/6/2026 | smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups. | |
| Modificada | Alta (7.5) | 65% | 💥 Exploit | Wp-ecommerce Easy WP Smtp | 14/12/2020 | 17/6/2026 | The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links.… | |
| Modificada | Crítica (9.8) | 89% | 💥 Exploit | OpensmtpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 25/2/2020 | 17/6/2026 | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling. | |
| Modificada | Media (4.7) | 0.90% | 💥 Exploit | OpensmtpdFedoraproject FedoraCanonical Ubuntu Linux | 25/2/2020 | 17/6/2026 | OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Openbsd OpensmtpdDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 29/1/2020 | 17/6/2026 | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists… | |
| Modificada | Crítica (9.8) | 2.9% | — | Libesmtp Project Libesmtp | 26/12/2019 | 17/6/2026 | libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read. | |
| Modificada | Media (6.1) | 1.0% | — | Postman-smtp Project Postman-smtp | 10/9/2019 | 17/6/2026 | The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter. | |
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Bestwebsoft Smtp | 20/8/2019 | 17/6/2026 | The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues. | |
| Modificada | Media (5.3) | 0.92% | — | Marlam MpopMarlam Msmtp | 13/2/2019 | 17/6/2026 | In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked. |