Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.46%—Feuerhamster MailformAI15/6/202617/6/2026
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
AnalizadaMedia (6.3)0.39%—Synck Mailform PRO CGI26/5/202517/6/2026
Mailform Pro CGI prior to 4.3.4 generates error messages containing sensitive information, which may allow a remote unauthenticated attacker to obtain coupon codes. This vulnerability only affects products that use the coupon feature.
ModificadaAlta (7.5)0.89%—Synck Graphica Mailform PRO CGI25/8/202317/6/2026
Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-of-service condition. Affected add-ons are as follows: call/call.js, prefcodeadv/search.cgi, estimate/estimate.js, search/search.js,…
ModificadaAlta (7.5)1.3%—Synck Mailform PRO CGI29/6/202317/6/2026
Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
ModificadaCrítica (9.8)1.3%—Microengine Mailform23/5/202317/6/2026
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
ModificadaCrítica (9.8)0.92%—Microengine Mailform23/5/202317/6/2026
Unrestricted upload of file with dangerous type exists in MicroEngine Mailform version 1.1.0 to 1.1.8. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
ModificadaMedia (5.9)1.5%—Synck Mailform PRO CGI8/9/202217/6/2026
Mailform Pro CGI 4.3.1 and earlier allow a remote unauthenticated attacker to obtain the user input data by having a use of the product to access a specially crafted URL.
ModificadaMedia (6.1)0.95%—Econosys-system PHP Mailform8/2/202217/6/2026
Reflected cross-site scripting vulnerability in the checkbox of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (6.1)0.95%—Econosys-system PHP Mailform8/2/202217/6/2026
Reflected cross-site scripting vulnerability in the attached file name of php_mailform versions prior to Version 1.40 allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaMedia (6.1)0.78%—Mailform01 Project Mailform0124/5/202117/6/2026
Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 July 27) allows a remote attacker to inject an arbitrary script via unspecified vectors.
ModificadaCrítica (9.8)2.3%—Mailform25/3/202017/6/2026
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
ModificadaMedia (6.1)0.77%—Mailform25/3/202017/6/2026
Cross-site scripting vulnerability in mailform version 1.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)2.3%—Synck Graphica Mailform PRO CGI27/2/201517/6/2026
SYNCK GRAPHICA Mailform Pro CGI 4.1.4 and 4.1.5, when the mailauth module is enabled, does not properly send e-mail messages, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)0.93%—PHP Kobo Multifunctional Mailform Free20/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in PHP Kobo Multifunctional MailForm Free 2014/1/28 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP Referer header.
ModificadaMedia (4.3)1.1%—H-fj Mailform Plugin4/1/201216/6/2026
Cross-site scripting (XSS) vulnerability in the MailForm plugin before 1.20 for Movable Type allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.0%—Scripts.bdr130 Mailform9/10/201116/6/2026
PHP remote file inclusion vulnerability in index.php in MailForm 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter.
ModificadaMedia (4.3)0.85%—Sebastian Winterhalder Mailform15/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the Mailform (mailform) extension before 0.9.24 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.6%—Ranson Johnson Mailform14/11/200016/6/2026
mailform.pl CGI script in MailForm 2.0 allows remote attackers to read arbitrary files by specifying the file name in the XX-attach_file parameter, which MailForm then sends to the attacker.