Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Alta (7.5) | 0.47% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 16/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.53% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.62% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Pendiente de análisis | Crítica (9.8) | 0.40% | — | Cisco Secure Email GatewayAICisco Secure Email AND WEB ManagerAI | 14/9/2026 | 15/9/2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered… | |
| Aplazada | Alta (8.6) | 0.64% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 4/9/2026 | SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges. | |
| Aplazada | Alta (7.7) | 0.47% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor. | |
| Aplazada | Alta (8.6) | 1.2% | — | Seppmail Secure Email GatewayAI | 3/9/2026 | 3/9/2026 | SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges. | |
| Aplazada | Alta (7.5) | 0.24% | — | Seppmail Secure Email GatewayAISeppmail CloudAI | 17/7/2026 | 17/7/2026 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header. | |
| Aplazada | Media (6.9) | 0.54% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 exposes server environment variables through an unauthenticated endpoint in the new GINA UI, allowing remote attackers to obtain sensitive system information. | |
| Aplazada | Alta (8.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains a server-side template injection vulnerability in the new GINA UI because an endpoint accepts attacker-controlled template, allowing remote attackers to execute arbitrary template expressions and potentially achieve remote code execution depending on the… | |
| Aplazada | Crítica (9.3) | 0.73% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.2.1 allows unauthenticated remote code execution in the new GINA UI because an endpoint passes attacker-controlled input from a parameter to Perl's eval. | |
| Aplazada | Alta (8.8) | 0.54% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 contains an unauthenticated path traversal vulnerability in the identifier parameter of /api.app/attachment/preview that allows remote attackers to read arbitrary local files and trigger deletion of files in the targeted directory with the privileges of the api.app… | |
| Aplazada | Crítica (9.2) | 0.76% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 insecurely deserializes untrusted data, which can be reached from the new GINA UI and may allow unauthenticated remote attackers to execute code via a crafted serialized object. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Seppmail Secure Email GatewayAI | 8/5/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.4 fails to enforce authorization checks for multiple endpoints in the new GINA UI, allowing unauthenticated remote attackers to access functionality that should require a valid session. | |
| Aplazada | Alta (8.8) | 0.56% | — | WP Mail GatewayAI | 2/5/2026 | 17/6/2026 | The WP Mail Gateway plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wmg_save_provider_config AJAX action in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update SMTP settings and… | |
| Analizada | Alta (7.8) | 0.35% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge security tags using Unicode lookalike characters. | |
| Analizada | Alta (7.8) | 0.43% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers. | |
| Analizada | Media (6.3) | 0.19% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email. | |
| Analizada | Alta (7.7) | 0.35% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK]. | |
| Analizada | Alta (7.7) | 0.19% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures. | |
| Analizada | Alta (7.8) | 0.48% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password. | |
| Analizada | Media (6.3) | 0.37% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own. | |
| Analizada | Media (5.3) | 0.31% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject. | |
| Analizada | Media (5.3) | 0.16% | — | Seppmail Secure Email Gateway | 2/4/2026 | 17/6/2026 | SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to inject HTML into notification emails about new CA certificates. |