Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
4597 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.37% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin. | |
| Analizada | Crítica (9.8) | 0.58% | — | Roundcube Webmail | 17/8/2026 | 10/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation. | |
| Analizada | Alta (7.1) | 2.3% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection. | |
| Analizada | Media (5.8) | 0.47% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation. | |
| Analizada | Media (5.4) | 0.30% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. | |
| Analizada | Alta (7.2) | 0.44% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing. | |
| Analizada | Alta (8.8) | 1.1% | — | Roundcube Webmail | 17/8/2026 | 8/9/2026 | In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver. | |
| Aplazada | Baja (2) | 0.41% | — | TraildbAI | 16/8/2026 | 20/8/2026 | A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early… | |
| Pendiente de análisis | Media (5.1) | 0.55% | — | Rails Html SanitizerAI | 13/8/2026 | 18/9/2026 | rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default… | |
| Aplazada | Alta (7.6) | 0.38% | — | Mailchimp FOR WoocommerceAI | 13/8/2026 | 14/8/2026 | Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Media (6.5) | 0.34% | — | Acymailing Smtp NewsletterAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Mailchimp Subscribe FormsAI | 13/8/2026 | 14/8/2026 | Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions. | |
| Aplazada | Crítica (9.8) | 0.50% | — | Wpfactory Customer Email Verification FOR WoocommerceAI | 13/8/2026 | 26/8/2026 | The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered… | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP. | |
| Pendiente de análisis | Alta (7.8) | 0.26% | — | Sonicwall Email SecurityAI | 11/8/2026 | 28/8/2026 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask. | |
| Aplazada | Alta (8.8) | 0.66% | — | AcymailingAI | 11/8/2026 | 12/8/2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it… | |
| Aplazada | Media (6.9) | 0.40% | — | AIL Project AILAI | 6/8/2026 | 26/8/2026 | AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and post identifiers directly into inline JavaScript onclick handlers: onclick="translateMessageToPreferredLanguage('{{ message['id'] }}',… | |
| Aplazada | Media (6.9) | 0.40% | — | AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to display a stored screenshot, without context-appropriate encoding. An attacker who can cause a specially crafted URL to be recorded in the… | |
| Aplazada | Alta (8.2) | 0.40% | — | Circl AIL FrameworkAI | 6/8/2026 | 26/8/2026 | AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error… | |
| Aplazada | Alta (8.6) | 0.41% | — | Constantcontact Creative MailAI | 6/8/2026 | 26/8/2026 | The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail. | |
| Aplazada | Media (6.5) | 0.22% | — | MailoptinAI | 6/8/2026 | 12/8/2026 | Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions. | |
| Aplazada | Alta (8.5) | 0.36% | — | Constantcontact Creative MailAI | 6/8/2026 | 12/8/2026 | Subscriber SQL Injection in Creative Mail <= 1.6.9 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | Kadence Woocommerce Email DesignerAI | 6/8/2026 | 12/8/2026 | Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions. | |
| Aplazada | Alta (8.1) | 0.49% | — | Mailchimp Forms BY MailmunchAI | 5/8/2026 | 12/8/2026 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and… |