Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.42% | — | Aleswebs Admail Multilingual Back IN Stock Notifier FOR WoocommerceAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in aleswebs AdMail – Multilingual Back in-Stock Notifier for WooCommerce admail allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AdMail – Multilingual Back in-Stock Notifier for WooCommerce: from n/a through <= 1.7.0. | |
| Aplazada | Alta (7.8) | 0.16% | — | Zedmail FOR WindowsAI | 15/11/2024 | 17/6/2026 | By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZEDMAIL has to be modified to prevent this vulnerability. | |
| Modificada | Media (6.1) | 0.35% | — | Iredmail Iredadmin | 23/9/2024 | 17/6/2026 | iRedAdmin before 2.6 allows XSS, e.g., via order_name. | |
| Aplazada | Alta (7.4) | 0.25% | — | Toshiba PrintersAISendmailAI | 14/6/2024 | 17/6/2026 | Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration file. As for the affected products/models/versions, see the reference URL. | |
| Modificada | Media (5.3) | 1.1% | — | SendmailFreebsdRedhat Enterprise Linux | 24/12/2023 | 17/6/2026 | sendmail through 8.17.2 allows SMTP smuggling in certain configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because sendmail supports <LF>.<CR><LF> but some other popular… | |
| Modificada | Media (5.5) | 0.23% | — | Primx Zed!Primx ZedmailPrimx Zonecentral | 13/12/2023 | 17/6/2026 | ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; ZED!… | |
| Modificada | Media (5.3) | 0.52% | — | Primx Zed!Primx ZedmailPrimx Zonecentral | 13/12/2023 | 17/6/2026 | ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before 2023.5, or ZEDMAIL for Windows before 2023.5… | |
| Modificada | Alta (7.5) | 0.61% | — | Primx Zed!Primx ZedmailPrimx Zonecentral | 13/12/2023 | 17/6/2026 | By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before… | |
| Modificada | Alta (7.4) | 2.0% | — | F5 NginxSendmailVsftpd Project VsftpdFedoraproject Fedora+1 | 23/3/2022 | 17/6/2026 | ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the TCP/IP layer can redirect traffic from one subdomain to… | |
| Modificada | Media (5.3) | 1.1% | — | Primx ZEDPrimx ZedmailPrimx Zonecentral | 3/2/2019 | 17/6/2026 | Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANSSI qualification submission) before 6.1.2150, Zed Entreprise for Mac before 2.0.199, Zed Entreprise for Linux before 2.0.199, Zed Pro for Windows before 1.0.195, Zed Pro for Mac before 1.0.199, Zed… | |
| Modificada | Alta (7.5) | 1.7% | — | Iredmail | 13/3/2018 | 17/6/2026 | iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack appear to be exploitable via network connectivity. This vulnerability appears… | |
| Modificada | Alta (7.5) | 3.7% | — | Qualcomm Eudora Worldmail | 13/1/2015 | 17/6/2026 | Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command. | |
| Modificada | Baja (1.9) | 0.64% | — | FreebsdHpuxFedoraproject FedoraSendmail | 4/6/2014 | 17/6/2026 | The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program. | |
| Modificada | Alta (7.5) | 2.1% | — | Script-shop24 LM Starmail Paidmail | 25/8/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 0.95% | — | Script-shop24 LM Starmail Paidmail | 25/8/2010 | 16/6/2026 | SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Media (6.8) | 2.3% | — | Phppower TOP Paidmailer | 26/3/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (7.5) | 2.4% | — | Sendmail | 4/1/2010 | 16/6/2026 | sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers… | |
| Modificada | Media (5) | 13% | — | Sendmail | 5/5/2009 | 16/6/2026 | Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header. | |
| Modificada | Alta (7.8) | 2.3% | — | Sendmail | 25/4/2007 | 16/6/2026 | Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows remote attackers to cause a denial of service via unknown attack vectors. NOTE: due to the lack of details from HP, it is not known whether this issue is a duplicate of… | |
| Modificada | Media (4.3) | 2.0% | — | Sendmail | 27/3/2007 | 16/6/2026 | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not reject the "localhost.localdomain" domain name for e-mail messages that come from external hosts, which might allow remote attackers to spoof messages. | |
| Modificada | Alta (7.5) | 0.82% | — | Sendmail | 27/3/2007 | 16/6/2026 | The version of Sendmail 8.13.1-2 on Red Hat Enterprise Linux 4 Update 4 and earlier does not allow the administrator to disable SSLv2 encryption, which could cause less secure channels to be used than desired. | |
| Modificada | Alta (10) | 7.1% | — | Eudora Worldmail Management Server | 31/12/2006 | 16/6/2026 | Heap-based buffer overflow in the Mail Management Server (MAILMA.exe) in Eudora WorldMail 3.1.x allows remote attackers to execute arbitrary code via a crafted request containing successive delimiters. | |
| Modificada | Crítica (9.8) | 0.98% | — | Qualcomm Eudora Worldmail | 21/11/2006 | 16/6/2026 | Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) "Eudora WorldMail stack overflow" and (2) "Eudora WorldMail heap overflow" modules in VulnDisco Pack. NOTE: Some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 0.92% | — | Qualcomm Eudora Worldmail | 21/11/2006 | 16/6/2026 | QUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. As of 20061118, this disclosure has no actionable information.… | |
| Modificada | Alta (7.5) | 4.5% | — | Sendmail | 29/8/2006 | 16/6/2026 | Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying "The only denial of service that is… |