Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

177 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Wp-ecommerce Easy WP Smtp6/12/202217/6/2026
Auth. Remote Code Execution vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
ModificadaMedia (6.5)0.84%—Wp-ecommerce Easy WP Smtp6/12/202217/6/2026
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
ModificadaAlta (8.1)0.90%—Wp-ecommerce Easy WP Smtp6/12/202217/6/2026
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
ModificadaAlta (7.2)1.2%—Wp-ecommerce Easy WP Smtp31/10/202217/6/2026
The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
ModificadaAlta (7.2)1.3%—Wpexperts Post Smtp26/9/202217/6/2026
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.7 does not have proper authorisation in some AJAX actions, which could allow high privilege users such as admin to perform blind SSRF on multisite installations for example.
ModificadaMedia (4.8)0.68%—Wpexperts Post Smtp16/9/202217/6/2026
The Post SMTP Mailer/Email Log WordPress plugin before 2.1.4 does not escape some of its settings before outputting them in the admins dashboard, allowing high privilege users to perform Cross-Site Scripting attacks against other users even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)0.61%—Yaycommerce Yaysmtp8/8/202217/6/2026
The YaySMTP WordPress plugin before 2.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.61%—Yaycommerce Yaysmtp8/8/202217/6/2026
The YaySMTP WordPress plugin before 2.2.1 does not have proper authorisation when saving its settings, allowing users with a role as low as subscriber to change them, and use that to conduct Stored Cross-Site Scripting attack due to the lack of escaping in them as well.
ModificadaMedia (6.5)0.92%—Yaycommerce Yaysmtp1/8/202217/6/2026
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the Mailer Credentials in JS code for the settings, allowing any authenticated users, such as subscriber to retrieve them
ModificadaMedia (4.3)0.72%—Yaycommerce Yaysmtp1/8/202217/6/2026
The YaySMTP WordPress plugin before 2.2.1 does not have capability check in an AJAX action, allowing any logged in users, such as subscriber to view the Logs of the plugin
ModificadaMedia (6.5)0.53%—Webriti Smtp Mail13/6/202217/6/2026
The Webriti SMTP Mail WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
ModificadaMedia (6.1)0.80%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe14/2/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.31 does not escape the lang and pid parameter before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaMedia (6.1)0.81%—Brevo Newsletter, Smtp, Email Marketing AND Subscribe24/1/202217/6/2026
The Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue WordPress plugin before 3.1.25 does not escape the sib-statistics-date parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.62%—Wpmanageninja Fluentsmtp30/8/202117/6/2026
The FluentSMTP WordPress plugin before 2.0.1 does not sanitize parameters before storing the settings in the database, nor does the plugin escape the values before outputting them when viewing the SMTP settings set by this plugin, leading to a stored cross site scripting (XSS) vulnerability. Only users with roles…
ModificadaMedia (6.5)0.56%—Netexplorer MY Smtp Contact10/8/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
ModificadaAlta (7.5)3.7%—OpensmtpdFedoraproject Fedora24/12/202017/6/2026
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and…
ModificadaAlta (7.5)2.9%—OpensmtpdFedoraproject Fedora24/12/202017/6/2026
smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups.
ModificadaAlta (7.5)65%💥 ExploitWp-ecommerce Easy WP Smtp14/12/202017/6/2026
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in December 2020. If an attacker can list the wp-content/plugins/easy-wp-smtp/ directory, then they can discover a log file (such as #############_debug_log.txt) that contains all password-reset links.…
ModificadaCrítica (9.8)89%💥 ExploitOpensmtpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux25/2/202017/6/2026
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling.
ModificadaMedia (4.7)0.90%💥 ExploitOpensmtpdFedoraproject FedoraCanonical Ubuntu Linux25/2/202017/6/2026
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitOpenbsd OpensmtpdDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux29/1/202017/6/2026
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM field. This affects the "uncommented" default configuration. The issue exists…
ModificadaCrítica (9.8)2.9%—Libesmtp Project Libesmtp26/12/201917/6/2026
libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as demonstrated by a stack-based buffer over-read.
ModificadaMedia (6.1)1.0%—Postman-smtp Project Postman-smtp10/9/201917/6/2026
The postman-smtp plugin through 2017-10-04 for WordPress has XSS via the wp-admin/tools.php?page=postman_email_log page parameter.
ModificadaMedia (6.1)1.6%💥 ExploitBestwebsoft Smtp20/8/201917/6/2026
The bws-smtp plugin before 1.1.0 for WordPress has multiple XSS issues.
ModificadaMedia (5.3)0.92%—Marlam MpopMarlam Msmtp13/2/201917/6/2026
In msmtp 1.8.2 and mpop 1.4.3, when tls_trust_file has its default configuration, certificate-verification results are not properly checked.
Orbitaley — Vulnerabilidades