Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
895 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.4) | 0.24% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service. | |
| Pendiente de análisis | Media (6.5) | 0.26% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither… | |
| Pendiente de análisis | Media (6.6) | 0.41% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and… | |
| Pendiente de análisis | Alta (7.2) | 0.39% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code… | |
| Pendiente de análisis | Alta (7.2) | 0.39% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account. | |
| Pendiente de análisis | Alta (7.5) | 0.21% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to… | |
| Pendiente de análisis | Alta (7) | 0.19% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including… | |
| Pendiente de análisis | Alta (7.2) | 0.64% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account. | |
| Pendiente de análisis | Alta (7.2) | 0.47% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an… | |
| Pendiente de análisis | Crítica (9.1) | 0.37% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account… | |
| Pendiente de análisis | Crítica (9.1) | 0.34% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| Pendiente de análisis | Crítica (9.1) | 0.23% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| Pendiente de análisis | Crítica (9.1) | 0.23% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| Pendiente de análisis | Crítica (9.1) | 0.27% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise… | |
| Pendiente de análisis | Alta (7.2) | 0.71% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary… | |
| Pendiente de análisis | Crítica (9.1) | 0.27% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could… | |
| Pendiente de análisis | Alta (7.2) | 0.47% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load… | |
| Pendiente de análisis | Alta (7.2) | 0.50% | — | Kiteworks Email Protection GatewayAI | 30/9/2026 | 1/10/2026 | Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system. | |
| Aplazada | Media (4.3) | 0.25% | — | Omnisend Newsletters Email Marketing SMS AND PopupsAI | 30/9/2026 | 30/9/2026 | Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions. | |
| Aplazada | Alta (7.2) | 0.40% | — | Kadencewp Kadence Woocommerce Email DesignerAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Kadence WooCommerce Email Designer <= 1.5.19.1 versions. | |
| Pendiente de análisis | Alta (8.2) | 0.25% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the… | |
| Pendiente de análisis | Media (6) | 0.11% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same non-IP host with different tls.servername values, the first transport's… | |
| Pendiente de análisis | Alta (8.7) | 0.28% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service… | |
| Pendiente de análisis | Media (6.9) | 0.19% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-separated domain atoms to be retained in the normalized address. For… |