Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.45% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | |
| Aplazada | Media (5.1) | 0.26% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | |
| Analizada | Alta (8.7) | 0.20% | — | Bouncycastle Bc-javaBouncycastle Bcjmail-fipsBouncycastle Bcmail-fipsBouncycastle Bouncy Castle FOR Java LTS | 3/8/2026 | 28/8/2026 | In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series), 2.0.7 (2.0.X series) and 2.1.7 (2.1.X… | |
| Aplazada | Alta (8.2) | 0.36% | — | Agenticmail ClaudecodeAIAgenticmail CoreAICodexnotes CodexAIOpenclawAI | 20/7/2026 | 23/7/2026 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to version 0.1.33, @agenticmail/core prior to version 0.9.43, and @agenticmail/openclaw prior to version 0.5.71, two inbound-mail handlers act on a privileged effect without… | |
| Aplazada | Alta (7.1) | 0.37% | — | AgenticmailAI | 20/7/2026 | 23/7/2026 | AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=<name>`. The returned… | |
| Aplazada | Alta (8.2) | 0.25% | — | Agenticmail CoreAIAgenticmailAI | 20/7/2026 | 23/7/2026 | AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to validation and and binding of inactive-agent hour filtering; storage SQL identifier validation; metadata-backed ownership checks for raw… | |
| Aplazada | Alta (8.7) | 0.54% | — | Agenticmail MCPAI | 12/6/2026 | 17/6/2026 | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode, the /mcp endpoint accepts requests without any HTTP authentication layer. A remote client can initialize a session and… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Acmailer CGIAIAcmailer DBAI | 18/2/2025 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlier and acmailer DB ver.1.1.5 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker. | |
| Aplazada | Media (6.1) | 0.29% | — | Acmailer CGIAI | 12/2/2025 | 17/6/2026 | Cross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on the web browser of the user who accessed the management page of the affected product. | |
| Modificada | Crítica (9.8) | 3.3% | — | AcmailerAcmailer DB | 14/1/2021 | 17/6/2026 | Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors. | |
| Modificada | Crítica (9.8) | 7.9% | — | AcmailerAcmailer DB | 14/1/2021 | 17/6/2026 | Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors. | |
| Modificada | Crítica (9.8) | 13% | — | Procmail | 16/11/2017 | 17/6/2026 | Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618. | |
| Modificada | Crítica (9.1) | 2.4% | — | Seeds Acmailer | 16/1/2016 | 17/6/2026 | Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Media (5.5) | 1.6% | — | Seeds Acmailer | 19/7/2015 | 17/6/2026 | Directory traversal vulnerability in Seeds acmailer before 3.8.18 and 3.9.x before 3.9.12 Beta allows remote authenticated users to delete arbitrary files via a crafted string. | |
| Modificada | Alta (7.5) | 8.5% | — | ProcmailCanonical Ubuntu Linux | 8/9/2014 | 17/6/2026 | Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes." | |
| Modificada | Media (6.8) | 0.92% | — | Seeds Acmailer | 29/7/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in CGI programs in Seeds acmailer before 3.8.17 and 3.9.x before 3.9.10 Beta allow remote attackers to hijack the authentication of arbitrary users for requests that modify or delete data, as demonstrated by modifying data affecting authorization. | |
| Modificada | Alta (9.3) | 9.3% | — | Youngzsoft Cmailserver | 10/8/2009 | 16/6/2026 | Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary code via a long argument to the (1) CreateUserPath, (2) Logout, (3) DeleteMailByUID, (4) MoveToInbox, (5) MoveToFolder, (6) DeleteMailEx, (7) GetMailDataEx, (8) SetReplySign, (9) SetForwardSign, and… | |
| Modificada | Alta (7.5) | 2.2% | — | Cicoandcico Ccmail | 22/4/2008 | 16/6/2026 | Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie. | |
| Modificada | Media (4.3) | 1.0% | — | Youngzsoft Cmailserver | 12/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mail/signup.asp in CmailServer WebMail 5.4.3, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the Comment parameter, a different vector than CVE-2007-1927. | |
| Modificada | Media (4.3) | 1.2% | — | Youngzsoft Cmailserver | 10/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.asp in CmailServer WebMail 5.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the POP3Mail parameter. | |
| Modificada | Media (6.8) | 2.6% | — | Cicoandcico Ccmail | 20/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the functions_dir parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Triexa Sonicmailer PRO | 13/3/2007 | 16/6/2026 | SQL injection vulnerability in index.php in Triexa SonicMailer Pro 3.2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the list parameter in an archive action. | |
| Modificada | Alta (10) | 5.0% | — | Youngzsoft CmailserverAI | 10/1/2005 | 16/6/2026 | Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachment with a long filename. | |
| Modificada | Media (6.8) | 1.3% | — | Youngzsoft Cmailserver | 10/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin.asp in CMailServer 5.2 allows remote attackers to execute arbitrary web script or HTML via personal information fields, such as (1) username, (2) name, or (3) comments. | |
| Modificada | Alta (10) | 1.9% | — | Youngzsoft Cmailserver | 10/1/2005 | 16/6/2026 | SQL injection vulnerability in (1) fdelmail.asp, (2) addressc.asp, and possibly (3) postmail.asp and (4) fmvmail.asp in CMailServer 5.2 allow remote attackers to inject arbitrary SQL commands and delete mail metadata or e-mail addresses of contacts via the indexOfMail parameter. |