Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.2) | 0.25% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, allowing attackers to cause stack exhaustion. Attackers can supply a deeply nested JSON recipient array that triggers recursive Array.toString() conversion, exhausting the call stack and terminating the… | |
| Pendiente de análisis | Media (6) | 0.11% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each cache entry also stores the caller-specific TLS servername. When two direct TLS/SMTPS transports (secure: true) resolve the same non-IP host with different tls.servername values, the first transport's… | |
| Pendiente de análisis | Alta (8.7) | 0.28% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service… | |
| Pendiente de análisis | Media (6.9) | 0.19% | — | NodemailerAI | 26/9/2026 | 30/9/2026 | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser) mishandles addresses whose local-part is a quoted string and that are followed by RFC 5322 comments, allowing trailing comment-separated domain atoms to be retained in the normalized address. For… | |
| Aplazada | Media (4.3) | 0.16% | — | MailerliteAI | 24/9/2026 | 24/9/2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1.7.21. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (5.1) | 0.18% | — | Uvdesk Core-frameworkAISwiftmailerAI | 21/9/2026 | 24/9/2026 | UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script into the identifier field, which is persisted and executed when other members… | |
| Pendiente de análisis | Alta (8.3) | 0.40% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain… | |
| Pendiente de análisis | Alta (8.3) | 0.38% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the… | |
| Pendiente de análisis | Alta (8.7) | 0.82% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for… | |
| Pendiente de análisis | Media (6) | 0.29% | — | NodemailerAI | 16/9/2026 | 22/9/2026 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key,… | |
| Pendiente de análisis | Alta (8.7) | 0.68% | — | NodemailerAI | 13/9/2026 | 24/9/2026 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and block the Node.js event loop for several… | |
| Pendiente de análisis | Alta (8.9) | 0.51% | — | LaravelAISymfony MailerAISymfony MimeAI | 4/9/2026 | 10/9/2026 | Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in… | |
| Aplazada | Baja (3.5) | 0.29% | — | PhpmailerAIWallosapp WallosAI | 31/8/2026 | 8/9/2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no server-side SSRF validation. When the scheduled… | |
| Pendiente de análisis | Crítica (9.3) | 2.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM command (as SIZE=...) without… | |
| Pendiente de análisis | Media (6.9) | 1.0% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer versions before 8.0.5 contain an SMTP command injection vulnerability in the transport name option used in EHLO/HELO commands. The name parameter is concatenated directly into SMTP commands without sanitizing carriage return and line feed characters, allowing attackers to inject arbitrary SMTP commands for… | |
| Pendiente de análisis | Alta (8.3) | 0.19% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.8 disables TLS certificate verification in lib/fetch/index.js through rejectUnauthorized: false, allowing attackers to intercept OAuth2 token requests. Attackers in a machine-in-the-middle position can capture OAuth client secrets, refresh tokens, and access tokens transmitted over compromised… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to sanitize carriage return and line feed characters in list comment fields, allowing attackers to inject arbitrary message headers. An attacker with control over list.*.comment parameters can inject CRLF sequences to create additional headers in generated RFC822 messages, altering mail… | |
| Pendiente de análisis | Media (5.3) | 0.26% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | Nodemailer before 8.0.9 fails to enforce disableFileAccess and disableUrlAccess options during message normalization in jsonTransport. Attackers can read local files or fetch URLs by supplying path or href values in message content fields, bypassing intended access controls. | |
| Pendiente de análisis | Alta (7.1) | 0.35% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or… | |
| Pendiente de análisis | Media (6.9) | 0.30% | — | NodemailerAI | 31/8/2026 | 10/9/2026 | nodemailer before 6.9.9 contains a regular expression denial of service vulnerability in email parsing when attachDataUrls parameter is set or processing embedded file attachments. Attackers can send specially crafted emails with malicious data URLs or embedded attachments to cause the event loop to hang and deny… | |
| Aplazada | Alta (8.7) | 0.45% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | An incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privileges. | |
| Aplazada | Media (5.1) | 0.26% | — | AcmailerAI | 19/8/2026 | 28/8/2026 | A cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script. | |
| Aplazada | Media (6.9) | 0.74% | — | Maalfer MailerupAI | 18/8/2026 | 1/9/2026 | HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the first_name field of the subscription… | |
| Aplazada | Media (4.9) | 0.44% | — | Icegram MailerAI | 1/8/2026 | 12/8/2026 | The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and including, 1.0.12. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the Icegram_Mailer_Logs_Table::get_logs()… | |
| Aplazada | Media (5.3) | 0.39% | — | MailerpressAI | 31/7/2026 | 12/8/2026 | The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `mailerpress/v1/contact` endpoint in all versions up to, and including, 1.5.0. This makes it possible for unauthenticated attackers to update contact details. |