Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
–

4600 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)——Pusula Communication Expert MailAI6/10/20266/10/2026
Improper Control of Interaction Frequency vulnerability in Pusula Communication, IT, and Internet Industry and Trade Co. Ltd. Expert Mail allows Brute Force. This issue affects Expert Mail: through 2026-09-18.
AplazadaMedia (5.3)0.25%—Mailjet Email MarketingAI6/10/20266/10/2026
Unauthenticated Sensitive Data Exposure in Mailjet Email Marketing <= 6.2.3 versions.
AplazadaAlta (7.1)0.24%—Wpmailster WP MailsterAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in WP Mailster <= 1.9.0.0 versions.
AplazadaMedia (5.3)0.19%—Wpmailster WP MailsterAI5/10/20266/10/2026
Missing Authorization vulnerability in WP Mailster WP Mailster wp-mailster allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Mailster: from n/a through 1.9.0.0.
AplazadaAlta (7.2)0.24%—Jamesward WP Mail CatcherAI3/10/20266/10/2026
The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer 'wp_mail_failed' Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
AplazadaMedia (5.3)0.22%—Mailchimp FOR WoocommerceAI3/10/20266/10/2026
The Mailchimp for WooCommerce WordPress plugin before 6.3 does not require authentication, a nonce or an ownership check before it acts on a customer's abandoned-cart record identified from request-supplied data, allowing an unauthenticated attacker to modify or delete another customer's stored cart.
AplazadaMedia (4.3)0.22%—Awesomemotive WP Mail LoggingAI2/10/20262/10/2026
The WP Mail Logging WordPress plugin before 1.17.0 does not properly restrict the HTML and CSS of logged emails before rendering them in its admin log screens, allowing unauthenticated users to inject styled content and links, for example through a public contact form, that can deceive an administrator viewing the log…
AplazadaAlta (8.7)0.26%—Sakailms SakaiAI1/10/20266/10/2026
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site…
AnalizadaCrítica (9.8)2.2%⚠ Explotación activaFortinet Fortimail1/10/20262/10/2026
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system…
AplazadaAlta (8.6)0.34%—Acymailing Smtp NewsletterAI1/10/20261/10/2026
Unauthenticated Arbitrary File Deletion in AcyMailing SMTP Newsletter <= 11.0.5 versions.
En análisisCrítica (9.4)0.24%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is…
En análisisMedia (5.3)0.36%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.
En análisisMedia (6.5)0.26%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither…
En análisisMedia (6.6)0.41%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and…
En análisisAlta (7.2)0.39%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code…
En análisisAlta (7.2)0.39%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.
En análisisAlta (7.5)0.21%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to…
En análisisAlta (7)0.19%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including…
En análisisAlta (7.2)0.64%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
En análisisAlta (7.2)0.47%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an…
En análisisCrítica (9.1)0.37%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account…
En análisisCrítica (9.1)0.34%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.23%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.23%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…
En análisisCrítica (9.1)0.27%—Kiteworks Email Protection GatewayAI30/9/20261/10/2026
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise…