Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.9)0.40%—AIL Project AILAI6/8/202626/8/2026
AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affected templates inserted message and post identifiers directly into inline JavaScript onclick handlers: onclick="translateMessageToPreferredLanguage('{{ message['id'] }}',…
AnalizadaMedia (6.5)0.31%—Admin Audit Trail Project Admin Audit Trail11/6/202517/6/2026
Allocation of Resources Without Limits or Throttling vulnerability in Drupal Admin Audit Trail allows Excessive Allocation.This issue affects Admin Audit Trail: from 0.0.0 before 1.0.5.
ModificadaCrítica (9.8)0.68%—WP Reroute Email Project WP Reroute Email6/11/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sajjad Hossain WP Reroute Email allows SQL Injection.This issue affects WP Reroute Email: from n/a through 1.4.6.
ModificadaAlta (8.8)0.25%—WP Reroute Email Project WP Reroute Email17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions.
ModificadaMedia (6.1)0.46%—WP Reroute Email Project WP Reroute Email12/7/202317/6/2026
The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
ModificadaMedia (4.8)0.39%—Wpfrom Email Project Wpfrom Email6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPGear.Pro WPFrom Email plugin <= 1.8.8 versions.
ModificadaMedia (6.1)0.63%—Resend Welcome Email Project Resend Welcome Email12/2/202317/6/2026
A vulnerability, which was classified as problematic, has been found in atwellpub Resend Welcome Email Plugin 1.0.1 on WordPress. This issue affects the function send_welcome_email_url of the file resend-welcome-email.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading…
ModificadaMedia (5.4)0.65%—Cloak Front END Email Project Cloak Front END Email6/2/202317/6/2026
The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaMedia (6.5)0.53%—Wp-email Project Wp-email20/6/202217/6/2026
The WP-EMail WordPress plugin before 2.69.0 does not protect its log deletion functionality with nonce checks, allowing attacker to make a logged in admin delete logs via a CSRF attack
ModificadaAlta (7.5)1.2%—Wp-email Project Wp-email20/6/202217/6/2026
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.
ModificadaAlta (7.8)0.39%—Firejail Project FirejailFedoraproject FedoraDebian Linux9/6/202217/6/2026
A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the…
ModificadaAlta (8.1)1.4%—Visual Voice Mail Project Visual Voice Mail25/2/202217/6/2026
The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the AOSP SMS/MMS messaging application.…
ModificadaMedia (6.1)0.94%—User-activation-email Project User-activation-email9/9/202117/6/2026
The User Activation Email WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the uae-key parameter found in the ~/user-activation-email.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.3.0.
ModificadaAlta (7)0.44%—Firejail Project FirejailDebian Linux8/2/202117/6/2026
Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race condition between a stat operation and an OverlayFS mount operation.
ModificadaAlta (7.5)0.79%—Winmail Project Winmail26/1/202117/6/2026
A SSRF vulnerability exists in Winmail 6.5 in app.php in the key parameter when HTTPS is on. An attacker can use this vulnerability to cause the server to send a request to a specific URL. An attacker can modify the request header 'HOST' value to cause the server to send the request.
ModificadaMedia (6.1)0.60%—Winmail Project Winmail26/1/202117/6/2026
A reflected XSS vulnerability exists in tohtml/convert.php of Winmail 6.5, which can cause JavaScript code to be executed.
ModificadaCrítica (9.8)4.1%—Firejail Project FirejailDebian LinuxFedoraproject FedoraOpensuse Leap11/8/202017/6/2026
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
ModificadaAlta (7.8)1.5%—Firejail Project FirejailDebian LinuxFedoraproject FedoraOpensuse Leap11/8/202017/6/2026
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
ModificadaMedia (4.3)1.1%—Basic Webmail Project Basic Webmail8/2/202016/6/2026
The Basic webmail module 6.x-1.x before 6.x-1.2 for Drupal allows remote authenticated users with the "access basic_webmail" permission to read arbitrary users' email addresses.
ModificadaCrítica (9.8)34%—HM Email Project HM EmailEq-3 Homematic Ccu2 FirmwareEq-3 Homematic Ccu3 Firmware14/11/201917/6/2026
eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution by unauthenticated attackers with access to the web interface via the save.cgi script for payload upload and the testtcl.cgi script for its execution.
ModificadaAlta (8.1)0.92%—Archivemail Project ArchivemailDebian Linux6/11/201916/6/2026
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
ModificadaMedia (6.5)1.1%—Alo-easymail Project Alo-easymail25/9/201917/6/2026
The alo-easymail plugin before 2.6.01 for WordPress has CSRF with resultant XSS in pages/alo-easymail-admin-options.php.
ModificadaMedia (6.1)0.91%—Check Email Project Check Email27/8/201917/6/2026
The check-email plugin before 0.5.2 for WordPress has XSS.
ModificadaAlta (8.8)0.51%—Firejail Project Firejail3/6/201917/6/2026
In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restrictions for a process that is joined to the jail after a filter has been modified by an attacker.
ModificadaAlta (8.1)2.0%—Firejail Project Firejail31/5/201917/6/2026
Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit code inside a firejail sandbox and having the sandbox terminated. To succeed, certain conditions need to be fulfilled: The jail (with the exploit code inside) needs to be started as root, and it also…