Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
4611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.49% | — | Hgiga Oaklouds Mailsherlock | 27/3/2023 | 17/6/2026 | HGiga MailSherlock’s specific function has insufficient filtering for user input. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript, conducting a reflected XSS attack. | |
| Modificada | Media (5.4) | 0.43% | — | Openfind Mail2000 | 27/3/2023 | 17/6/2026 | Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can exploit this vulnerability to inject JavaScript, conducting an XSS attack. | |
| Modificada | Alta (8) | 0.46% | — | Tailscale | 23/3/2023 | 17/6/2026 | Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2 in FreeBSD allows commands to be run with a higher privilege group ID than that specified in Tailscale SSH access… | |
| Modificada | Media (5.4) | 0.38% | — | Galaxyweblinks Gallery With Thumbnail Slider | 21/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions. | |
| Modificada | Media (4.8) | 0.39% | — | WP Better Emails Project WP Better Emails | 20/3/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nicolas Lemoine WP Better Emails plugin <= 0.4 versions. | |
| Modificada | Crítica (9.8) | 1.2% | — | Kamailio | 15/3/2023 | 17/6/2026 | The Kamailio SIP before 5.5.0 server mishandles INVITE requests with duplicated fields and overlength tag, leading to a buffer overflow that crashes the server or possibly have unspecified other impact. | |
| Modificada | Media (5.3) | 1.8% | 💥 PoC | Fortinet Fortimail | 9/3/2023 | 17/6/2026 | A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending numerous HTTP requests to the login form. | |
| Modificada | Crítica (9.8) | 0.63% | — | Email Registration Project Email Registration | 6/3/2023 | 16/6/2026 | A vulnerability was found in Email Registration 5.x-2.1 on Drupal. It has been declared as critical. This vulnerability affects the function email_registration_user of the file email_registration.module. The manipulation of the argument namenew leads to sql injection. The attack can be initiated remotely. Upgrading to… | |
| Modificada | Alta (8.8) | 2.2% | — | Mailcow\ | 4/3/2023 | 17/6/2026 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - which can be made available to standard users by assigning them the necessary permission - suffers from a shell command injection. A malicious user can abuse this vulnerability to obtain shell access… | |
| Modificada | Media (6.7) | 0.45% | 💥 PoC | Cisco Email Security Appliance | 1/3/2023 | 17/6/2026 | Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A… | |
| Modificada | Alta (7.2) | 1.3% | 💥 PoC | Cisco Email Security ApplianceCisco Secure Email AND WEB Manager | 1/3/2023 | 17/6/2026 | A vulnerability in the Web UI and administrative CLI of the Cisco Secure Email Gateway (ESA) and Cisco Secure Email and Web Manager (SMA) could allow an authenticated remote attacker and or authenticated local attacker to escalate their privilege level and gain root access. The attacker has to have a valid user… | |
| Modificada | Crítica (9.8) | 1.1% | — | Harrys Dynosaur-rails | 21/2/2023 | 17/6/2026 | A vulnerability has been found in harrystech Dynosaur-Rails and classified as critical. Affected by this vulnerability is the function basic_auth of the file app/controllers/application_controller.rb. The manipulation leads to improper authentication. This product does not use versioning. This is why information about… | |
| Modificada | Alta (8.8) | 0.36% | — | Submitbymailplugin Project Submitbymailplugin | 20/2/2023 | 17/6/2026 | A vulnerability was found in arnoldle submitByMailPlugin 1.0b2.9 and classified as problematic. This issue affects some unknown processing of the file edit_list.php. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. Upgrading to version 1.0b2.9a is able to address this issue.… | |
| Modificada | Crítica (9.9) | 1.1% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates. | |
| Modificada | Media (5.4) | 0.60% | — | Jenkins Email Extension | 15/2/2023 | 17/6/2026 | Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields. | |
| Modificada | Media (6.5) | 0.47% | — | Tibco HawkTibco Operational Intelligence Hawk Redtail | 14/2/2023 | 17/6/2026 | The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains a vulnerability that will return the EMS transport password and EMS SSL password to a privileged user. Affected releases are TIBCO Software Inc.'s TIBCO Hawk: versions 6.1.0 through 6.2.1 and TIBCO… | |
| Modificada | Media (5.3) | 0.72% | — | Sonicwall Email Security | 14/2/2023 | 17/6/2026 | SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive information about users email addresses. | |
| Modificada | Media (5.3) | 0.46% | — | Nextcloud Mail | 13/2/2023 | 17/6/2026 | Nextcloud Mail is an email app for the Nextcloud home server platform. Prior to versions 2.2.1, 1.14.5, 1.12.9, and 1.11.8, an attacker can access the mail box by ID getting the subjects and the first characters of the emails. Users should upgrade to Mail 2.2.1 for Nextcloud 25, Mail 1.14.5 for Nextcloud 22-24, Mail… | |
| Modificada | Alta (7.5) | 0.78% | — | Akindo-sushiro Hong Kong SushiroAkindo-sushiro Singapore SushiroAkindo-sushiro SushiroAkindo-sushiro Taiwan Sushiro+1 | 13/2/2023 | 17/6/2026 | SUSHIRO App for Android outputs sensitive information to the log file, which may result in an attacker obtaining a credential information from the log file. Affected products/versions are as follows: SUSHIRO Ver.4.0.31, Thailand SUSHIRO Ver.1.0.0, Hong Kong SUSHIRO Ver.3.0.2, Singapore SUSHIRO Ver.2.0.0, and Taiwan… | |
| Modificada | Media (6.1) | 0.63% | — | Resend Welcome Email Project Resend Welcome Email | 12/2/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading… | |
| Modificada | Alta (7) | 0.14% | — | HP 348 G4 FirmwareHP 260 G2 Desktop Mini FirmwareHP 218 PRO G5 MT FirmwareHP 260 G3 Desktop Mini Firmware+21 | 12/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.5) | 1.0% | — | Rubyonrails Globalid | 9/2/2023 | 17/6/2026 | A ReDoS based DoS vulnerability in the GlobalID <1.0.1 which could allow an attacker supplying a carefully crafted input can cause the regular expression engine to take an unexpected amount of time. All users running an affected release should either upgrade or use one of the workarounds immediately. | |
| Modificada | Media (6.1) | 0.60% | — | Actionpack Project ActionpackRubyonrails Rails | 9/2/2023 | 17/6/2026 | An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a… | |
| Modificada | Alta (7.5) | 2.3% | — | Rubyonrails RailsDebian Linux | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Action Dispatch <6.1.7.1 and <7.0.4.1 related to the If-None-Match header. A specially crafted HTTP If-None-Match header can cause the regular expression engine to enter a state of catastrophic backtracking, when on a version of Ruby below 3.2.0. This can cause the… |