Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

4597 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.3)0.37%—Roundcube Webmail17/8/20268/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
AnalizadaCrítica (9.8)0.58%—Roundcube Webmail17/8/202610/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.
AnalizadaAlta (7.1)2.3%—Roundcube Webmail17/8/20268/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
AnalizadaMedia (5.8)0.47%—Roundcube Webmail17/8/20268/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
AnalizadaMedia (5.4)0.30%—Roundcube Webmail17/8/20268/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
AnalizadaAlta (7.2)0.44%—Roundcube Webmail17/8/20268/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
AnalizadaAlta (8.8)1.1%—Roundcube Webmail17/8/20268/9/2026
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
AplazadaBaja (2)0.41%—TraildbAI16/8/202620/8/2026
A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early…
Pendiente de análisisMedia (5.1)0.55%—Rails Html SanitizerAI13/8/202618/9/2026
rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restricted SVG reference elements in SVG_ALLOW_LOCAL_HREF only when they used xlink:href, even though browsers also accept the plain href attribute. Applications with non-default…
AplazadaAlta (7.6)0.38%—Mailchimp FOR WoocommerceAI13/8/202614/8/2026
Administrator SQL Injection in MailChimp For WooCommerce < 6.2 versions.
AplazadaMedia (6.5)0.22%—Acymailing Smtp NewsletterAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= 10.11.1 versions.
AplazadaMedia (6.5)0.34%—Acymailing Smtp NewsletterAI13/8/202614/8/2026
Subscriber Broken Access Control in AcyMailing SMTP Newsletter <= 10.11.1 versions.
AplazadaAlta (7.1)0.25%—Mailchimp Subscribe FormsAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
AplazadaCrítica (9.8)0.50%—Wpfactory Customer Email Verification FOR WoocommerceAI13/8/202626/8/2026
The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and take over the account of any registered…
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.
Pendiente de análisisAlta (7.8)0.26%—Sonicwall Email SecurityAI11/8/202628/8/2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
AplazadaAlta (8.8)0.66%—AcymailingAI11/8/202612/8/2026
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaMedia (6.9)0.40%—AIL Project AILAI6/8/202626/8/2026
AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and post identifiers directly into inline JavaScript onclick handlers: onclick="translateMessageToPreferredLanguage('{{ message['id'] }}',…
AplazadaMedia (6.9)0.40%—AIL FrameworkAI6/8/202626/8/2026
AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScript onclick handler used to display a stored screenshot, without context-appropriate encoding. An attacker who can cause a specially crafted URL to be recorded in the…
AplazadaAlta (8.2)0.40%—Circl AIL FrameworkAI6/8/202626/8/2026
AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag operation, the application returned the error value directly as an HTML response using str(res[0]). If attacker-controlled input was included in the generated error…
AplazadaAlta (8.6)0.41%—Constantcontact Creative MailAI6/8/202626/8/2026
The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.
AplazadaMedia (6.5)0.22%—MailoptinAI6/8/202612/8/2026
Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.
AplazadaAlta (8.5)0.36%—Constantcontact Creative MailAI6/8/202612/8/2026
Subscriber SQL Injection in Creative Mail <= 1.6.9 versions.
AplazadaCrítica (9.8)0.48%—Kadence Woocommerce Email DesignerAI6/8/202612/8/2026
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
AplazadaAlta (8.1)0.49%—Mailchimp Forms BY MailmunchAI5/8/202612/8/2026
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and…