Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
3269 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mailchimp Subscribe FormsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 13/8/2026 | 26/8/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. | |
| Aplazada | Alta (8.8) | 0.66% | — | AcymailingAI | 11/8/2026 | 12/8/2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Alta (8.6) | 0.41% | — | Constantcontact Creative MailAI | 6/8/2026 | 26/8/2026 | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | |
| Aplazada | Media (6.5) | 0.22% | — | MailoptinAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Constantcontact Creative MailAI | 6/8/2026 | 12/8/2026 | Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Aplazada | Alta (8.1) | 0.49% | — | Mailchimp Forms BY MailmunchAI | 5/8/2026 | 12/8/2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Aplazada | Media (6.1) | 0.36% | — | Soliton Systems Mailzen Management PortalAI | 4/8/2026 | 31/8/2026 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Username fields. | |
| Aplazada | Baja (1.9) | 0.21% | — | Blix Email Blue Mail Calendar APPAIReact Native Receive Sharing IntentAI | 3/8/2026 | 12/8/2026 | A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path traversal. The attack is only possible with… | |
| Analizada | Alta (8.7) | 0.20% | — | Bouncycastle Bc-javaBouncycastle Bcjmail-fipsBouncycastle Bcmail-fipsBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X… | |
| Aplazada | Media (4.9) | 0.44% | — | Icegram MailerAI | 1/8/2026 | 12/8/2026 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs()… | |
| Aplazada | Alta (7.2) | 0.42% | — | Pluginops Mailchimp Subscribe FormAI | 1/8/2026 | 12/8/2026 | The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers… | |
| Aplazada | Media (6.4) | 0.35% | — | Sendpulse Email Marketing NewsletterAI | 1/8/2026 | 12/8/2026 | The SendPulse Email Marketing Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via _sp_form_code Post Meta in all versions up to, and including, 2.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level… | |
| Aplazada | Media (5.3) | 0.39% | — | MailerpressAI | 31/7/2026 | 12/8/2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details. | |
| Aplazada | Media (5.3) | 0.39% | — | MailpressAI | 31/7/2026 | 12/8/2026 | The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore REST endpoint (POST /wp-json/mailpress/v1/campaign/<id>/restore-revision/<revision_id>). The route in the vulnerable range was registered without a permissionCallback,… | |
| Aplazada | Media (6.5) | 0.27% | — | Mailgun FOR WordpressAI | 31/7/2026 | 26/8/2026 | The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's… | |
| Aplazada | Media (6.5) | 0.40% | — | Check LOG EmailAI | 31/7/2026 | 26/8/2026 | The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing users with administrator privileges to perform SQL injection attacks. | |
| Aplazada | Alta (7.1) | 0.55% | — | Courier ImapAICourier Mail ServerAI | 29/7/2026 | 30/7/2026 | Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesized SEARCH queries. The SEARCH command parser (alloc_search_key in searchinfo.C) recursively descends on nested parenthesized groups through a mutual recursion chain with… | |
| Aplazada | Alta (7.1) | 0.13% | — | MailpoetAI | 23/7/2026 | 23/7/2026 | Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0. | |
| Aplazada | Crítica (9.1) | 0.50% | — | MailsterAI | 23/7/2026 | 23/7/2026 | Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. |