Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.47% | — | Inbox Foundry Activeinbox ExtensionAI | 31/8/2026 | 31/8/2026 | A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The… | |
| Analizada | Baja (2.3) | 0.31% | — | Getinboxzero Inbox Zero | 11/5/2026 | 17/6/2026 | Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated account to another authenticated account using the cleaner feature at the same time. This vulnerability is fixed in… | |
| Analizada | Alta (8.6) | 0.23% | — | Viafirma Inbox | 12/1/2026 | 17/6/2026 | IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password recovery functionality to access the… | |
| Aplazada | Media (5.9) | 0.21% | — | Inboxify Sign UP FormAI | 30/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Inboxify Inboxify Sign Up Form inboxify-sign-up-form allows Stored XSS.This issue affects Inboxify Sign Up Form: from n/a through <= 1.0.4. | |
| Aplazada | Alta (7.1) | 0.28% | — | Wppluginbox Stylish Google Sheet ReaderAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wppluginboxdev Stylish Google Sheet Reader stylish-google-sheet-reader allows Reflected XSS.This issue affects Stylish Google Sheet Reader: from n/a through <= 4.0. | |
| Analizada | Alta (7.1) | 0.27% | — | Wppluginbox Stylish Google Sheet Reader | 25/3/2025 | 17/6/2026 | The Stylish Google Sheet Reader 4.0 WordPress plugin before 4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Crítica (9.8) | 1.5% | — | Gosecure Titan Inbox Detection & Response | 25/8/2022 | 17/6/2026 | Key reuse in GoSecure Titan Inbox Detection & Response (IDR) through 2022-04-05 leads to remote code execution. To exploit this vulnerability, an attacker must craft and sign a serialized payload. | |
| Modificada | Media (5.5) | 0.38% | — | Mikrotik Winbox | 15/4/2020 | 17/6/2026 | MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by default Master Password is not set. An attacker with access to the configuration file can extract a… | |
| Modificada | Media (5.9) | 1.1% | — | Mikrotik Winbox | 6/2/2020 | 17/6/2026 | MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle attack. | |
| Modificada | Baja (3.7) | 1.1% | — | Mikrotik RouterosMikrotik Winbox | 14/1/2020 | 17/6/2026 | MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password. | |
| Modificada | Baja (3.8) | 0.33% | — | Vmware Airwatch AgentVmware Airwatch Inbox | 10/5/2017 | 17/6/2026 | Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data. | |
| Modificada | Alta (8.8) | 0.35% | — | Vmware Airwatch AgentVmware Airwatch Inbox | 10/5/2017 | 17/6/2026 | Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data. | |
| Modificada | Media (5) | 19% | — | Wowjoomla COM Loginbox | 12/4/2010 | 16/6/2026 | Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. | |
| Modificada | Media (4.6) | 0.83% | — | Positive Software H-sphere Winbox | 16/5/2005 | 16/6/2026 | H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges. | |
| Modificada | Media (5) | 3.2% | — | Linbit Technologies Linbox Officeserver | 30/3/2004 | 16/6/2026 | LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a direct request to admin/user.pl preceded by // (double leading slash). |