Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
–

4611 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.49%—Hgiga Oaklouds Mailsherlock27/3/202317/6/2026
HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack.
ModificadaMedia (5.4)0.43%—Openfind Mail200027/3/202317/6/2026
Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack.
ModificadaAlta (8)0.46%—Tailscale23/3/202317/6/2026
Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2 in FreeBSD allows commands to be run with a higher privilege group ID than that specified in Tailscale SSH access…
ModificadaMedia (5.4)0.38%—Galaxyweblinks Gallery With Thumbnail Slider21/3/202317/6/2026
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions.
ModificadaMedia (4.8)0.39%—WP Better Emails Project WP Better Emails20/3/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 versions.
ModificadaCrítica (9.8)1.2%—Kamailio15/3/202317/6/2026
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact.
ModificadaMedia (5.3)1.8%💥 PoCFortinet Fortimail9/3/202317/6/2026
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form.
ModificadaCrítica (9.8)0.63%—Email Registration Project Email Registration6/3/202316/6/2026
A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to sql injection. The attack can be initiated remotely. Upgrading to…
ModificadaAlta (8.8)2.2%—Mailcow\4/3/202317/6/2026
mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse this vulnerability to obtain shell access…
ModificadaMedia (6.7)0.45%💥 PoCCisco Email Security Appliance1/3/202317/6/2026
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A…
ModificadaAlta (7.2)1.3%💥 PoCCisco Email Security ApplianceCisco Secure Email AND WEB Manager1/3/202317/6/2026
A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user…
ModificadaCrítica (9.8)1.1%—Harrys Dynosaur-rails21/2/202317/6/2026
A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about…
ModificadaAlta (8.8)0.36%—Submitbymailplugin Project Submitbymailplugin20/2/202317/6/2026
A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the file edit_list.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 1.0b2.9a is able to address this issue.…
ModificadaCrítica (9.9)1.1%—Jenkins Email Extension15/2/202317/6/2026
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
ModificadaMedia (5.4)0.60%—Jenkins Email Extension15/2/202317/6/2026
Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.
ModificadaMedia (5.4)0.60%—Jenkins Email Extension15/2/202317/6/2026
Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.
ModificadaMedia (6.5)0.47%—Tibco HawkTibco Operational Intelligence Hawk Redtail14/2/202317/6/2026
The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO…
ModificadaMedia (5.3)0.72%—Sonicwall Email Security14/2/202317/6/2026
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses.
ModificadaMedia (5.3)0.46%—Nextcloud Mail13/2/202317/6/2026
Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail…
ModificadaAlta (7.5)0.78%—Akindo-sushiro Hong Kong SushiroAkindo-sushiro Singapore SushiroAkindo-sushiro SushiroAkindo-sushiro Taiwan Sushiro+113/2/202317/6/2026
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan…
ModificadaMedia (6.1)0.63%—Resend Welcome Email Project Resend Welcome Email12/2/202317/6/2026
A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading…
ModificadaAlta (7)0.14%—HP 348 G4 FirmwareHP 260 G2 Desktop Mini FirmwareHP 218 PRO G5 MT FirmwareHP 260 G3 Desktop Mini Firmware+2112/2/202317/6/2026
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.
ModificadaAlta (7.5)1.0%—Rubyonrails Globalid9/2/202317/6/2026
A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately.
ModificadaMedia (6.1)0.60%—Actionpack Project ActionpackRubyonrails Rails9/2/202317/6/2026
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a…
ModificadaAlta (7.5)2.3%—Rubyonrails RailsDebian Linux9/2/202317/6/2026
A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the…